Repository navigation
Codex 0.159.3 -> 0.160.0 with the Python SDK pair: pins, qualification receipt, tests and checkpoint - #626
Conversation
…n receipt, tests and checkpoint Moves the Linux Codex pin and the coupled SDK pair (openai-codex and openai-codex-cli-bin) to rust-v0.160.0 (a956835d020762cb2b570053af06f643a11c0ecc), with a new qualification receipt (runtime-sdk-20261003): npm wrapper integrity, native binary sha256, strict-hash SDK install from a repository-root lock compile, and native-account, gateway SDK and gateway CLI marker canaries on this host. macOS stays 0.155.1; the shared host launcher and daemon still run 0.159.3 until a coordinated switch. Reviewed by Opus (changes-needed, repaired in one round) and GPT-6.1 Sol (accept). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…tocol, last commit) Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
Trading-lane acknowledgement requested. This PR changes exactly one trading-owned line: Separately, for the trading owner and not changed here: The previous move, #580, was acknowledged the same way (comment of 2026-10-01T18:00:03Z). |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 511168f4ae
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
Findings at exact head 511168f, base 56473e4. This is a direct source/artifact read, not a new provider or SDK run. The pin and marker-canary record is separate from complete role qualification. The public receipt and qualification artifact explicitly use coordinator-supplied qualification facts, with no returned-output hashes or SDK caller exits. The new artifact directory contains only that receipt; its retained-evidence pointer is to the older October1 receipt, whose scope correctly does not qualify0.160.0. No unchanged upstream checks are recorded. Thus I can inspect the declared marker/usage facts and their limitations, but have not independently observed the original0.160 native outputs or the frozen oracle/process record required by acceptance policy. Please hand off the retained sanitized original command/returned-output locators and hashes, exact managed executable/cwd/version binding, and any original process/SDK return record and discriminating controls that support the claimed native qualification. Original sensitive output can stay private; no credential/auth files are requested. Preserve genuinely missing exits/usage as unknown and label reported metadata accordingly. An artifact map is sufficient for my next bounded original-source read; no repeated model canaries or broad suites are requested by this finding. The three marker turns do not close the runtime goal's task-worker, researcher, reviewer, builder, MCP/deny and recoverable lifecycle roles. Old0.159.3 role evidence, synthetic0.160 test doubles and the production launcher/daemon still at0.159.3 retain their separate scopes. The runtime owner remains thread01a0ffbf-135b; it is preregistering the two comparisons and continuing the role lane. Requested gateway model/effort and backend observation remain separate as the receipt already says. Trading-owner ACK and fresh-main/hot-file reconciliation remain separate merge gates. This is a qualification-evidence finding; no whole SDK-lane ACCEPT is issued, and the retained source/installation facts are not discarded. The official pinned source is openai/codex rust-v0.160.0 at a956835d020762cb2b570053af06f643a11c0ecc, sdk/python and supported install/daemon interfaces. Root's native installed client observation still names0.159.3; no host switch is implied by this review. |
…form binary, retained native records, worker guide - adoption/bootstrap-linux.sh: npm pins with a platform_dependency now fetch the platform tarball, verify its sha256 and the registry SHA-512 integrity, install it in place of npm's unverified optional copy, and check the installed executable's sha256 before linking (ported from bootstrap-macos.sh install_platform_dependency); the codex pin carries the 0.160.0 linux-x64 platform dependency (sha256 37a41d61..., binary 12eb3e81...). New offline tests. - runtime-sdk-20261003: sanitized retained native records (canary outputs, CLI exec events, exec-help diff, npm metadata, exact invocations), a marker-check script with positive and negative controls, and hashes. - blueprints/us-equities/workers/README.md: current SDK statements moved to 0.160.0; the 2026-09-30 result kept as history (trading acknowledgement requested on the PR). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…rotocol, last commit) Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…) and the macOS canonical-path test fix - S1: before linking, the installed wrapper must map optionalDependencies[dep] to exactly npm:<platform package>@<version>, and node_modules may hold only the pinned packages; the alias target must be new and inside the prefix. - S2: ignore_scripts on the Linux codex pin (neither package has lifecycle scripts); pins that keep scripts get a full extracted-tree comparison after rebuild, failing closed on any difference. - S3: parity tests lock verify_sha256, fetch, canonical_path, prune_old_version, npm_package_name and install_npm between the Linux and macOS bootstraps (the macOS publication, pruning and cleanup paths took the shared fixes). - M1-M7: python3 prerequisite, isolated SHA-512 check, archive verified before npm install, migration state cleared after the swap, fresh versioned prefix with pruning guarded, tightened assertions and new negative controls. - A real bootstrap into a fresh isolated root exited 0 (4 verified, 0 failed); codex-cli 0.160.0, binary sha256 12eb3e81... - tests/test_adoption_bootstrap.py: NpmIgnoreScriptsTests expect the canonical prefix (hosted validate-macos at ad9787c failed on /private/var vs /var); reproduced and cleared on Linux with a symlinked TMPDIR. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
… commit) Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…-pin-20261003 # Conflicts: # manifests/evidence.json
|
Exact-head source/publication verdict for PR626: HEAD Consequential trigger: installer/binary provenance and platform verifier repairs. Native requested Astra/max first read3842 returned0 at source Current source/registration merge independently verified:81 PR-owned paths, all80 non-registry blobs unchanged; main retirement104 non-registry blobs inherited exactly. Native pinned API reads0; all80 owned bindings match bytes/hash,26updates/54adds/no removals,9383 other main file rows preserved; main187receipts plus branch receipt=188,26convergence paths unchanged. Current registry2517414bytes SHA256 The following is the native narrow followup final, with only its private original-file link replaced by a public-safe locator description. Original2872bytes SHA256 ACCEPT for this delta — the sole primary-source evidence-access block is closed. No remaining P1/P2 finding within this scope. This applies to HEAD
Root’s separate observation of the 4,902-byte release archive—three members, matching registry SHA-512, release metadata and byte-identical launcher—completes the package/source binding. This remains a parent observation, not a new upstream test or execution. All five cache files match preserved native exit-0 stdout plus exactly one newline; cache hashes are not raw-response hashes. The original BLOCK and failures (private originals retained), including DNS exit 6, remain preserved with 329,574 input / 245,760 cached subset / 14,705 output / 6,481 reasoning subset. Subsets are nonadditive; actual backend, effort and billing remain unknown. Completeness check: launcher, release binding and npm semantics are covered. Two read-only batches; no network or target execution. Original ownership boundaries, full SDK roles/recovery, hosted macOS CI, trading ACK and native host acceptance remain outside this delta. Required hosted checks, current trading ACK and fresh owner merge guards still govern landing. Parent source-fetch hook banners were retained and corrected through context-mode; they were not registry JSON or native package executions. No auth/credential files or active client configuration read/copied; no Claude-owned source edited. |
Trading shared scope ACK: PR626 current headACK exact head Original Git objects verify both merge parents: final release Compared with this lane's prior ACK at511168f4, the only worker-directory difference is README.md. Requirements remain byte-identical at SDK0.160.0; the trading policy, adaptive-paper and engine-nautilus trees are unchanged. The README's last change is A3 The guide correctly separates the upgraded pair's recorded compatibility attempt from historical SDK0.159.2 tool/thread-resume qualification. Missing original invocation/timing remains a limitation; marker compatibility does not qualify upgraded SDK roles, a trading workload, destination profile or paper broker operation. Its pinned upstream source is official Codex SDK a956835d/rust-v0.160.0. This ACK does not infer a fresh installed-client run from repository metadata. No local tests, installation, native model/provider/broker call, shared-path edit or credential read occurred. Unchanged prior evidence is reused within its original scope. Fresh required checks, exact-head/main/thread guards and the agreed root/Claude/0c merge order still govern merge. Reconsider this ACK if original source changes. Separate Monday paper hold is recorded at PR608#5966340913; no foundation change releases that hold. |
… validate-macos at ad02af0) validate-macos at ad02af0 errored in two A4 tests of tests/test_adoption_bootstrap_linux_platform.py: - test_failed_swap_restores_migrated_install_and_removes_unpublished_prefix: bootstrap-linux.sh restores a migrated install with GNU `mv -T` (lines 314 and 782); BSD mv has no -T, so the restore does not happen on macOS. - LinuxPrerequisiteTests.test_missing_python3_names_the_prerequisite_before_any_write: the shim links GNU/util-linux tools (flock, sha256sum); shutil.which returns None for flock on macOS, so symlink_to(None) raised TypeError. Both exercise behaviour of the Linux-only bootstrap; a GNU_ONLY skip with that reason keeps them on Linux, where they still run and pass. The macOS bootstrap has its own suite (tests.test_adoption_bootstrap_macos). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…commit) Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Trading ACK for PR #626 at 75a2adaObserved 2026-10-03T07:41Z. Scope: source and trading impact only. Renew the trading ACK for exact head 75a2ada, compared with the previously acknowledged ad02af0 and canonical main e88d59e. The bounded Sol/ultra source inspection found fourteen non-registry main carryovers with matching blobs, plus the Linux test module and its current registry record; it found no trading implementation, adoption recipe, stack selection or historical-receipt change. The branch-local source delta adds Unchanged worker README SHA256: No new local test, installation, provider/model run, broker request, shared-path edit or credential inspection was performed for this ACK. Required exact-head CI, current-main guards, unresolved-thread checks and the agreed owner merge order still apply. Any later source change requires renewed scope review. Monday's three order-writing timers remain held; this foundation ACK releases no paper gate. |
|
ACCEPT — source carryover at exact head The branch-owned change adds GNU_ONLY, using The full tree/registry map shows 81 accepted branch-owned paths: only that test module and the evidence registry differ, with no new branch-owned path. Main #639 contributes15 paths; only the registry overlaps, and the other14 match merged main byte-for-byte. Linux and macOS installers, Linux pins and SDK lock, The registry is current main plus the accepted owned delta and the changed test binding, with zero missing/unexpected/mismatched entries. It preserves9,387 peer file rows,187 peer receipts and26 convergence records in exact value/order. The updated test row binds28,940 bytes/SHA256 Native source observations and bounded map/dependency commands exited0; exact-head readback confirms75a2/basee88. Original API responses and map output remain retained with the source worker’s custody keys and this root receipt. No tests, provider run, native installation or SDK qualification were rerun. This ACCEPT covers the source delta and evidence preservation, not complete SDK role/cost/recovery/cancellation/restoration qualification or current CI. The owner’s merge slot after #637, required checks and exact |
Refresh onto main e7c297e (20 commits after 1f5a791, through #665), by the round-4 method and the hot-file protocol (docs/lanes.md): - .gitattributes: both sides kept. Main's codex-client-check entry comes first, then this branch's two exec-help entries at the end. No pattern repeats or contradicts another. - docs/new-wsl-handbook.{md,json} and the handbook receipt: main's copies (#659) are the base, then python3 scripts/build_new_wsl_handbook.py --write. In the receipt only profile_sha256 and the two outputs hashes change, to this branch's profile and the regenerated files. generator_sha256 stays main's a78239b6..., which is the hash of the unchanged generator. - manifests/evidence.json: main's copy, with this branch's receipts[] row runtime-sdk-20261003 appended. The two grand-list outputs are re-registered by new_host_grand_list.py --write, and this branch's other 85 files by host_receipts.register_file from the merged tree. Main's 9,658 other rows are unchanged and in main's order. - manifests/stack.json and observability/grand-dashboard/state.json: main has not changed them since 1f5a791, so this branch's copies stand. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…on before the last commit Sets the three shared hot files (docs/lanes.md) to origin/main e7c297e so that the next and last commit carries this branch's whole hot-file delta against main. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…ile protocol, last commit) Against main e7c297e: the Codex 0.160.0 pin and receipt list in manifests/stack.json; main's registry with this branch's rows applied, including the regenerated new-WSL handbook files and handbook receipt, in manifests/evidence.json; and in observability/grand-dashboard/state.json the two Codex 0.160.0 gate rows beside main's gates, with main's checkpoint time and its meaning extended by one passage. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
Claude session native-agent-stack-5f: head Commits. Pushed normally as
Main has since moved to How each conflict was resolved. The merge conflicted in four files, all of them expected.
(a) Mechanical refresh check,
|
| Row | 36d45155 |
a1a5488e |
|---|---|---|
.gitattributes |
bf64b1766971…, 855 B |
b056917f02d4…, 1,123 B |
adoption/platforms/macos-arm64.md |
afe35db07045…, 63,262 B |
07f57a25f609…, 64,072 B |
docs/new-wsl-handbook.json |
4728b0184183…, 537,182 B |
93682c255f4c…, 561,055 B |
docs/new-wsl-handbook.md |
b124bd55d65d…, 320,267 B |
73fff09e4c2d…, 323,968 B |
evidence/artifacts/new-wsl-handbook-20261001/receipt.json |
a68b7a3cc7bd…, 4,174 B |
e7154e3e62c3…, 4,174 B |
recipes/README.md |
fda04fef73bc…, 125,306 B |
94ccf5e86f0a…, 126,072 B |
tests/test_adoption_bootstrap_macos.py |
d142da3da639…, 228,055 B |
a085835f7fdf…, 228,690 B |
tests/test_codex_worker_lane.py |
3ba0ee57cacb…, 155,359 B |
b044dbd84257…, 155,728 B |
tests/test_render_config.py |
a6145567f5bc…, 43,257 B |
e8a7d735d730…, 45,406 B |
-
Receipts and convergence records. The PR's own
receipts[]row (runtime-sdk-20261003) is unchanged. The PR leavesconvergence_recordsuntouched, before and after. -
Integration-test inputs. Main changed these Codex-lane paths after
1f5a791b:adoption/templates/codex.AGENTS.template.mdandcodex.config.template.toml;adoption/agents/codex/workers/SHA256SUMSandsemantic-evidence-reviewer.toml;tests/test_codex_worker_lane.py;tools/adoption/codex_home.py,install_skills.pyandnew_wsl_client_config.py.
The real
CodexIntegrationTestswere therefore run again at this head; see (c).
(b) For the configuration owner's per-PR read: the exact handbook and receipt diff against main e7c297e2
The two handbook files come from --write with no hand edits. In the receipt, the three hashes are a hand edit, and nothing else changed. The json and md +/- lines are byte-identical to those in round 4's diff against 1f5a791b.
diff --git a/docs/new-wsl-handbook.json b/docs/new-wsl-handbook.json
index 74a41ae7c..8c2afd0b3 100644
--- a/docs/new-wsl-handbook.json
+++ b/docs/new-wsl-handbook.json
@@ -6828,7 +6828,7 @@
},
{
"path": "adoption/new-wsl-profile.json",
- "sha256": "1e08ba8e879b0c52fd5c53341ea60bb27ca70ebc64cb9af655d9ba5ae0a21cb0"
+ "sha256": "160d85512e237a2d2f65de752aed86dd1f4da8633fc77feb35324e7c4499d028"
},
{
"path": "adoption/platforms/linux-wsl2-new-distro.md",
@@ -7154,8 +7154,8 @@
"checksum": {
"algorithm": "sha256",
"kind": "artifact",
- "source": "https://registry.npmjs.org/%40openai%2Fcodex/0.159.3",
- "value": "31d5e584e93e118dd37dbb8bc89ddbbe9998178fc437dc0b9d0f7cc72ef0cf79"
+ "source": "https://registry.npmjs.org/%40openai%2Fcodex/0.160.0",
+ "value": "373517768e912eeb5054024ae9215e2c90a1420957b66fe134ef745a00948d4a"
},
"documented_install": [
{
@@ -7172,16 +7172,17 @@
"evidence/artifacts/new-wsl-clean-install-selection-20261001/selection.json",
"evidence/artifacts/new-wsl-clean-install-selection-20261001/packets/native-clients.json",
"evidence/artifacts/new-wsl-profile-20261001/source-review.json",
- "https://github.com/openai/codex/blob/rust-v0.159.3/README.md",
+ "https://github.com/openai/codex/blob/rust-v0.160.0/README.md",
"https://developers.openai.com/codex/noninteractive",
- "evidence/artifacts/new-wsl-profile-20261001/upstream-gap-closure.json"
+ "evidence/artifacts/new-wsl-profile-20261001/upstream-gap-closure.json",
+ "evidence/artifacts/runtime-sdk-20261003/receipt.json"
],
"install": {
- "command": "npm install -g @openai/codex@0.159.3",
+ "command": "npm install -g @openai/codex@0.160.0",
"execution_status": "UNRUN",
"pinning_source": "https://docs.npmjs.com/cli/v11/commands/npm-install",
"scope": "Upstream npm install form with the accepted package version supplied using npm documented version syntax. This is a reviewed example; the selected bootstrap keeps its existing isolated-prefix installation path.",
- "source": "https://github.com/openai/codex/blob/rust-v0.159.3/README.md"
+ "source": "https://github.com/openai/codex/blob/rust-v0.160.0/README.md"
},
"name": "Codex",
"native_update": {
@@ -7193,7 +7194,7 @@
"order": "It runs after the bootstrap has installed the pin and before this client's acceptance command.",
"receipt_fields": {
"acceptance_result_on_that_version": "The result of this entry's acceptance command on that version.",
- "floor": "The pin of this entry, 0.159.3: the release the bootstrap installs.",
+ "floor": "The pin of this entry, 0.160.0: the release the bootstrap installs.",
"version_after_native_update": "The version that PATH resolves to after the native update, or after the updater's refusal."
},
"sources": [
@@ -7203,7 +7204,7 @@
"owner_layer_id": "native-clients",
"ownership_source": "evidence/artifacts/new-wsl-clean-install-selection-20261001/ownership.json",
"package_id": "npm:@openai/codex",
- "pin": "0.159.3",
+ "pin": "0.160.0",
"position": 1,
"provisioning_status": "unprovisioned_source_review",
"repository": "https://github.com/openai/codex",
@@ -11041,7 +11042,7 @@
"Existing authorized native Codex authentication and the intended repository context."
],
"scope": "The Python body is the unchanged upstream quickstart; the here-document is only its shell carrier. No SDK/provider/model execution or output-quality acceptance occurred.",
- "source": "https://github.com/openai/codex/blob/rust-v0.159.3/sdk/python/README.md#quickstart"
+ "source": "https://github.com/openai/codex/blob/rust-v0.160.0/sdk/python/README.md#quickstart"
},
"aliases": [
"Codex Python SDK"
@@ -11050,8 +11051,8 @@
"checksum": {
"algorithm": "sha256",
"kind": "artifact",
- "source": "https://pypi.org/pypi/openai-codex/0.159.3/json",
- "value": "5148065fb13cfb3f106c6493f3a5dc26457da98f6350e193e85eda8b65263b8f"
+ "source": "https://pypi.org/pypi/openai-codex/0.160.0/json",
+ "value": "61d2d855ca2ebedfd51280fbeb60ff31fc47ccbd55ebce186505e3f3da096921"
},
"documented_install": [],
"evidence_refs": [
@@ -11059,22 +11060,23 @@
"evidence/artifacts/new-wsl-clean-install-selection-20261001/selection.json",
"evidence/artifacts/new-wsl-clean-install-selection-20261001/packets/agent-sdks.json",
"evidence/artifacts/new-wsl-profile-20261001/source-review.json",
- "https://github.com/openai/codex/blob/rust-v0.159.3/sdk/python/README.md",
- "evidence/artifacts/new-wsl-profile-20261001/upstream-gap-closure.json"
+ "https://github.com/openai/codex/blob/rust-v0.160.0/sdk/python/README.md",
+ "evidence/artifacts/new-wsl-profile-20261001/upstream-gap-closure.json",
+ "evidence/artifacts/runtime-sdk-20261003/receipt.json"
],
"install": {
- "command": "python -m pip install openai-codex==0.159.3",
+ "command": "python -m pip install openai-codex==0.160.0",
"execution_status": "UNRUN",
- "package_source": "https://pypi.org/pypi/openai-codex/0.159.3/json",
+ "package_source": "https://pypi.org/pypi/openai-codex/0.160.0/json",
"pinning_source": "https://pip.pypa.io/en/stable/cli/pip_install/",
"scope": "Upstream package installed using pip documented module invocation and exact version syntax; run in the owned Python environment, never the OS Python.",
- "source": "https://github.com/openai/codex/blob/rust-v0.159.3/sdk/python/README.md"
+ "source": "https://github.com/openai/codex/blob/rust-v0.160.0/sdk/python/README.md"
},
"name": "Codex Python SDK",
"owner_layer_id": "agent-sdks",
"ownership_source": "evidence/artifacts/new-wsl-clean-install-selection-20261001/ownership.json",
"package_id": "pypi:openai-codex",
- "pin": "0.159.3",
+ "pin": "0.160.0",
"position": 3,
"provisioning_status": "unprovisioned_source_review",
"repository": "https://github.com/openai/codex",
diff --git a/docs/new-wsl-handbook.md b/docs/new-wsl-handbook.md
index ae942df89..e362267fe 100644
--- a/docs/new-wsl-handbook.md
+++ b/docs/new-wsl-handbook.md
@@ -197,7 +197,7 @@ Default ownership: ["Claude Code", "Codex"]; uses: [].
| Tool / repository | Owner / status | Pin / checksum | Install | Acceptance | Stage / position |
| --- | --- | --- | --- | --- | --- |
| [Claude Code](https://github.com/anthropics/claude-code) | native-clients / picked | 2.1.284 / {"algorithm": "sha256", "kind": "artifact", "source": "https://downloads.claude.ai/claude-code-releases/2.1.284/manifest.json", "value": "5cd90aabd83f8a15136c35aa37bb1d92b348993573316643dc3fe4e04afbf88f"} | {"command": "curl -fsSL https://claude.ai/install.sh \| bash -s 2.1.284", "execution_status": "UNRUN", "scope": "The documented specific-version form with the accepted pin as its operand: the floor that the selected bootstrap installs through the native binary's own `install <version>`. The bootstrap keeps a newer existing install instead of downgrading it. This is a reviewed example; the move to the current release is the native update below.", "source": "https://code.claude.com/docs/en/setup#install-a-specific-version"} | {"command": "claude -p \"explain this function\"", "evidence_class": "documented_upstream_example_not_executed", "execution_status": "UNRUN", "prerequisites": ["Claude Code at or above the 2.1.284 floor installed, with its installed version recorded in the receipt.", "Existing authorized native sign-in and actual function/project context sufficient to answer the example."], "scope": "Official one-off query example. A prompt without actual function context is not a functional oracle. Host 2.1.287 is above the 2.1.284 floor and counts as installed; acceptance has not passed on that host. No model request occurred.", "source": "https://code.claude.com/docs/en/quickstart#essential-commands"} | native-clients / 2 |
-| [Codex](https://github.com/openai/codex) (`npm:@openai/codex`) | native-clients / picked | 0.159.3 / {"algorithm": "sha256", "kind": "artifact", "source": "https://registry.npmjs.org/%40openai%2Fcodex/0.159.3", "value": "31d5e584e93e118dd37dbb8bc89ddbbe9998178fc437dc0b9d0f7cc72ef0cf79"} | {"command": "npm install -g @openai/codex@0.159.3", "execution_status": "UNRUN", "pinning_source": "https://docs.npmjs.com/cli/v11/commands/npm-install", "scope": "Upstream npm install form with the accepted package version supplied using npm documented version syntax. This is a reviewed example; the selected bootstrap keeps its existing isolated-prefix installation path.", "source": "https://github.com/openai/codex/blob/rust-v0.159.3/README.md"} | {"command": "codex exec \"summarize the repository structure and list the top 5 risky areas\"", "evidence_class": "documented_upstream_example_not_executed", "execution_status": "UNRUN", "prerequisites": ["Selected Codex CLI and its native platform dependency installed.", "Existing authorized native sign-in and the intended repository context."], "scope": "Official noninteractive example. No model request, result-quality assessment, account activation or destination-host execution occurred.", "source": "https://developers.openai.com/codex/noninteractive"} | native-clients / 1 |
+| [Codex](https://github.com/openai/codex) (`npm:@openai/codex`) | native-clients / picked | 0.160.0 / {"algorithm": "sha256", "kind": "artifact", "source": "https://registry.npmjs.org/%40openai%2Fcodex/0.160.0", "value": "373517768e912eeb5054024ae9215e2c90a1420957b66fe134ef745a00948d4a"} | {"command": "npm install -g @openai/codex@0.160.0", "execution_status": "UNRUN", "pinning_source": "https://docs.npmjs.com/cli/v11/commands/npm-install", "scope": "Upstream npm install form with the accepted package version supplied using npm documented version syntax. This is a reviewed example; the selected bootstrap keeps its existing isolated-prefix installation path.", "source": "https://github.com/openai/codex/blob/rust-v0.160.0/README.md"} | {"command": "codex exec \"summarize the repository structure and list the top 5 risky areas\"", "evidence_class": "documented_upstream_example_not_executed", "execution_status": "UNRUN", "prerequisites": ["Selected Codex CLI and its native platform dependency installed.", "Existing authorized native sign-in and the intended repository context."], "scope": "Official noninteractive example. No model request, result-quality assessment, account activation or destination-host execution occurred.", "source": "https://developers.openai.com/codex/noninteractive"} | native-clients / 1 |
- claude verdict: pending; pending.
- codex verdict: pending; pending.
@@ -219,7 +219,7 @@ Reference edition: [catalogs/foundation/new-wsl-architecture-20261001.json](../c
- Claude Code receipt field acceptance_result_on_that_version: The result of this entry's acceptance command on that version.
- Claude Code packet install reference (not a pinned recipe): [{"command": "curl -fsSL https://claude.ai/install.sh \| bash", "source": "https://code.claude.com/docs/en/setup (setup.md lines 40-43, tab 'macOS, Linux, WSL'; read 2026-10-01)"}, {"command": "curl -fsSL https://claude.ai/install.sh \| bash", "source": "https://github.com/anthropics/claude-code/blob/main/README.md"}]
- Codex native update: `codex update`, UNRUN. `codex update --help` on codex-cli 0.159.3 prints: Update Codex to the latest version. It runs after the bootstrap has installed the pin and before this client's acceptance command. An updater that refuses is recorded with its error and the version actually on PATH. The anti-pattern log of docs/harness-defaults.md records that `codex update` did not establish that a versioned launcher's target had changed, so the version that PATH resolves to is read after the update and never assumed from it. The acceptance command then runs on the version that results. A release newer than the pin counts as installed and not yet qualified until that acceptance has passed on that host. Sources: [docs/harness-defaults.md](../docs/harness-defaults.md).
-- Codex receipt field floor: The pin of this entry, 0.159.3: the release the bootstrap installs.
+- Codex receipt field floor: The pin of this entry, 0.160.0: the release the bootstrap installs.
- Codex receipt field version_after_native_update: The version that PATH resolves to after the native update, or after the updater's refusal.
- Codex receipt field acceptance_result_on_that_version: The result of this entry's acceptance command on that version.
- Codex packet install reference (not a pinned recipe): [{"command": "npm install -g @openai/codex", "source": "https://github.com/openai/codex/blob/main/README.md line 42 (macOS alternative: brew install --cask codex, line 47); read 2026-10-01"}, {"command": "curl -fsSL https://chatgpt.com/codex/install.sh \| sh", "source": "https://github.com/openai/codex/blob/main/README.md"}]
@@ -299,7 +299,7 @@ Default ownership: []; uses: ["the native subagents of Claude Code and Codex (na
| Tool / repository | Owner / status | Pin / checksum | Install | Acceptance | Stage / position |
| --- | --- | --- | --- | --- | --- |
| [Claude Code](https://github.com/anthropics/claude-code) | native-clients / picked | 2.1.284 / {"algorithm": "sha256", "kind": "artifact", "source": "https://downloads.claude.ai/claude-code-releases/2.1.284/manifest.json", "value": "5cd90aabd83f8a15136c35aa37bb1d92b348993573316643dc3fe4e04afbf88f"} | {"command": "curl -fsSL https://claude.ai/install.sh \| bash -s 2.1.284", "execution_status": "UNRUN", "scope": "The documented specific-version form with the accepted pin as its operand: the floor that the selected bootstrap installs through the native binary's own `install <version>`. The bootstrap keeps a newer existing install instead of downgrading it. This is a reviewed example; the move to the current release is the native update below.", "source": "https://code.claude.com/docs/en/setup#install-a-specific-version"} | {"command": "claude -p \"explain this function\"", "evidence_class": "documented_upstream_example_not_executed", "execution_status": "UNRUN", "prerequisites": ["Claude Code at or above the 2.1.284 floor installed, with its installed version recorded in the receipt.", "Existing authorized native sign-in and actual function/project context sufficient to answer the example."], "scope": "Official one-off query example. A prompt without actual function context is not a functional oracle. Host 2.1.287 is above the 2.1.284 floor and counts as installed; acceptance has not passed on that host. No model request occurred.", "source": "https://code.claude.com/docs/en/quickstart#essential-commands"} | native-clients / 2 |
-| [Codex](https://github.com/openai/codex) (`npm:@openai/codex`) | native-clients / picked | 0.159.3 / {"algorithm": "sha256", "kind": "artifact", "source": "https://registry.npmjs.org/%40openai%2Fcodex/0.159.3", "value": "31d5e584e93e118dd37dbb8bc89ddbbe9998178fc437dc0b9d0f7cc72ef0cf79"} | {"command": "npm install -g @openai/codex@0.159.3", "execution_status": "UNRUN", "pinning_source": "https://docs.npmjs.com/cli/v11/commands/npm-install", "scope": "Upstream npm install form with the accepted package version supplied using npm documented version syntax. This is a reviewed example; the selected bootstrap keeps its existing isolated-prefix installation path.", "source": "https://github.com/openai/codex/blob/rust-v0.159.3/README.md"} | {"command": "codex exec \"summarize the repository structure and list the top 5 risky areas\"", "evidence_class": "documented_upstream_example_not_executed", "execution_status": "UNRUN", "prerequisites": ["Selected Codex CLI and its native platform dependency installed.", "Existing authorized native sign-in and the intended repository context."], "scope": "Official noninteractive example. No model request, result-quality assessment, account activation or destination-host execution occurred.", "source": "https://developers.openai.com/codex/noninteractive"} | native-clients / 1 |
+| [Codex](https://github.com/openai/codex) (`npm:@openai/codex`) | native-clients / picked | 0.160.0 / {"algorithm": "sha256", "kind": "artifact", "source": "https://registry.npmjs.org/%40openai%2Fcodex/0.160.0", "value": "373517768e912eeb5054024ae9215e2c90a1420957b66fe134ef745a00948d4a"} | {"command": "npm install -g @openai/codex@0.160.0", "execution_status": "UNRUN", "pinning_source": "https://docs.npmjs.com/cli/v11/commands/npm-install", "scope": "Upstream npm install form with the accepted package version supplied using npm documented version syntax. This is a reviewed example; the selected bootstrap keeps its existing isolated-prefix installation path.", "source": "https://github.com/openai/codex/blob/rust-v0.160.0/README.md"} | {"command": "codex exec \"summarize the repository structure and list the top 5 risky areas\"", "evidence_class": "documented_upstream_example_not_executed", "execution_status": "UNRUN", "prerequisites": ["Selected Codex CLI and its native platform dependency installed.", "Existing authorized native sign-in and the intended repository context."], "scope": "Official noninteractive example. No model request, result-quality assessment, account activation or destination-host execution occurred.", "source": "https://developers.openai.com/codex/noninteractive"} | native-clients / 1 |
| [Worktrunk](https://github.com/max-sixty/worktrunk) | git-github-automation / picked | 0.80.0 / {"algorithm": "sha256", "kind": "artifact", "source": "https://api.github.com/repos/max-sixty/worktrunk/releases/tags/v0.80.0", "value": "532ce3ed5eecb1be274c925b5887f61671e2434a4ca2561b9a8ac9379dbba199"} | {"command": "curl --proto '=https' --tlsv1.2 -LsSf https://github.com/max-sixty/worktrunk/releases/download/v0.80.0/worktrunk-installer.sh \| sh && wt config shell install", "execution_status": "UNRUN", "scope": "Exact versioned release-installer command including upstream wt config shell install. This writes shell integration when executed; no installer or shell mutation was run.", "source": "https://github.com/max-sixty/worktrunk/releases/tag/v0.80.0"} | {"command": "cargo test", "evidence_class": "upstream_test_command_not_executed", "execution_status": "UNRUN", "prerequisites": ["Selected upstream source checkout and Rust build/test dependencies."], "scope": "README default cargo test unit suite only; shell integration has a separate feature-enabled suite requiring bash, zsh, fish, nushell, pwsh and jq. No shell integration was qualified. The observed host release 0.79.0 is below the selected release 0.80.0; acceptance is owed on the new host.", "source": "https://github.com/max-sixty/worktrunk/blob/b49ca7eea9b03145791a5b94eccaf9c59412ed37/README.md"} | native-extensions / 4 |
- claude verdict: pending; pending.
@@ -322,7 +322,7 @@ Reference edition: [catalogs/foundation/new-wsl-architecture-20261001.json](../c
- Claude Code receipt field acceptance_result_on_that_version: The result of this entry's acceptance command on that version.
- Claude Code packet install reference (not a pinned recipe): [{"command": "curl -fsSL https://claude.ai/install.sh \| bash", "source": "https://code.claude.com/docs/en/setup (setup.md lines 40-43, tab 'macOS, Linux, WSL'; read 2026-10-01)"}, {"command": "curl -fsSL https://claude.ai/install.sh \| bash", "source": "https://github.com/anthropics/claude-code/blob/main/README.md"}]
- Codex native update: `codex update`, UNRUN. `codex update --help` on codex-cli 0.159.3 prints: Update Codex to the latest version. It runs after the bootstrap has installed the pin and before this client's acceptance command. An updater that refuses is recorded with its error and the version actually on PATH. The anti-pattern log of docs/harness-defaults.md records that `codex update` did not establish that a versioned launcher's target had changed, so the version that PATH resolves to is read after the update and never assumed from it. The acceptance command then runs on the version that results. A release newer than the pin counts as installed and not yet qualified until that acceptance has passed on that host. Sources: [docs/harness-defaults.md](../docs/harness-defaults.md).
-- Codex receipt field floor: The pin of this entry, 0.159.3: the release the bootstrap installs.
+- Codex receipt field floor: The pin of this entry, 0.160.0: the release the bootstrap installs.
- Codex receipt field version_after_native_update: The version that PATH resolves to after the native update, or after the updater's refusal.
- Codex receipt field acceptance_result_on_that_version: The result of this entry's acceptance command on that version.
- Codex packet install reference (not a pinned recipe): [{"command": "npm install -g @openai/codex", "source": "https://github.com/openai/codex/blob/main/README.md line 42 (macOS alternative: brew install --cask codex, line 47); read 2026-10-01"}, {"command": "curl -fsSL https://chatgpt.com/codex/install.sh \| sh", "source": "https://github.com/openai/codex/blob/main/README.md"}]
@@ -1163,7 +1163,7 @@ Default ownership: ["Claude Agent SDK", "Codex SDK and codex exec/app-server"];
| [Claude Agent SDK](https://github.com/anthropics/claude-agent-sdk-python) (`pypi:claude-agent-sdk`) | agent-sdks / picked | 0.2.163 / {"algorithm": "sha256", "kind": "artifact", "source": "https://pypi.org/pypi/claude-agent-sdk/0.2.163/json", "value": "269821ad5acff5967522ff15f444b0598840fd9bdc45c645de569a5478061a53"} | {"command": "pip install claude-agent-sdk==0.2.163", "execution_status": "UNRUN", "prerequisites": ["Owned Python environment and pip for claude-agent-sdk 0.2.163."], "source": "https://github.com/anthropics/claude-agent-sdk-python/blob/v0.2.163/README.md", "source_review_ref": "evidence/artifacts/new-wsl-profile-20261001/core-native-recipe-wave-1.json"} | {"command": "pip install -e \".[dev]\" && python -m pytest tests/ -v --cov=claude_agent_sdk --cov-report=xml", "evidence_class": "upstream_test_command_not_executed", "execution_status": "UNRUN", "prerequisites": ["Run from the v0.2.163 source checkout in the upstream Python test environment with its development extras.", "This selects tests/, not the separate authenticated e2e-tests/ workflow."], "scope": "Unchanged upstream source tests; no native sign-in, authenticated SDK turn, provider or new-host acceptance.", "source": "https://github.com/anthropics/claude-agent-sdk-python/blob/v0.2.163/.github/workflows/test.yml", "source_review_ref": "evidence/artifacts/new-wsl-profile-20261001/core-native-recipe-wave-1.json"} | sdk-source-review / 1 |
| [Codex SDK and codex exec/app-server](https://github.com/openai/codex) | agent-sdks / picked | pending / pending | pending | pending | None / None |
| [Codex TypeScript SDK](https://github.com/openai/codex) (`npm:@openai/codex-sdk`) | agent-sdks / picked | 0.159.3 / {"algorithm": "sha256", "kind": "artifact", "source": "https://registry.npmjs.org/%40openai%2Fcodex-sdk/0.159.3", "value": "f10a967cab205ad7875bd2cd8c508ccc5ab9501ff900f9466378e1b0e14b0522"} | {"command": "npm install @openai/codex-sdk@0.159.3", "execution_status": "UNRUN", "pinning_source": "https://docs.npmjs.com/cli/v11/commands/npm-install", "prerequisites": ["Owned Node/npm project environment for @openai/codex-sdk 0.159.3."], "scope": "Reviewed upstream package-manager form with the verified package release supplied as its explicit version.", "source": "https://github.com/openai/codex/blob/rust-v0.159.3/sdk/typescript/README.md", "source_review_ref": "evidence/artifacts/new-wsl-profile-20261001/core-native-recipe-wave-1.json"} | {"command": "pnpm install --frozen-lockfile && pnpm -r --filter ./sdk/typescript run build && pnpm -r --filter ./sdk/typescript run test", "evidence_class": "upstream_test_command_not_executed", "execution_status": "UNRUN", "prerequisites": ["Run from the rust-v0.159.3 repository root with the workflow's pnpm setup and Node.js 22.", "Complete the selected workflow's Bazel preparation and build //codex-rs/cli:codex plus //codex-rs/code-mode-host:codex-code-mode-host. Stage both matching binaries together and set CODEX_EXEC_PATH to that CLI as the workflow specifies; no environment or credential values were read here.", "The recorded install/build/test steps omit the separate lint step and do not reproduce the whole CI job."], "scope": "Upstream SDK source test workflow with its matching CLI/code-mode-host prerequisites; no live provider/sign-in or new-host result. Python SDK qualification does not qualify this TypeScript SDK.", "source": "https://github.com/openai/codex/blob/rust-v0.159.3/.github/workflows/sdk.yml#L126", "source_review_ref": "evidence/artifacts/new-wsl-profile-20261001/core-native-recipe-wave-1.json"} | sdk-source-review / 2 |
-| [Codex Python SDK](https://github.com/openai/codex) (`pypi:openai-codex`) | agent-sdks / picked | 0.159.3 / {"algorithm": "sha256", "kind": "artifact", "source": "https://pypi.org/pypi/openai-codex/0.159.3/json", "value": "5148065fb13cfb3f106c6493f3a5dc26457da98f6350e193e85eda8b65263b8f"} | {"command": "python -m pip install openai-codex==0.159.3", "execution_status": "UNRUN", "package_source": "https://pypi.org/pypi/openai-codex/0.159.3/json", "pinning_source": "https://pip.pypa.io/en/stable/cli/pip_install/", "scope": "Upstream package installed using pip documented module invocation and exact version syntax; run in the owned Python environment, never the OS Python.", "source": "https://github.com/openai/codex/blob/rust-v0.159.3/sdk/python/README.md"} | {"command": "python - <<'PY'\nfrom openai_codex import Codex\n\nwith Codex() as codex:\n thread = codex.thread_start()\n result = thread.run(\"Explain this repository in three bullets.\")\n print(result.final_response)\nPY", "evidence_class": "documented_upstream_example_not_executed", "execution_status": "UNRUN", "prerequisites": ["Owned Python environment with the selected SDK and its native CLI dependency installed.", "Existing authorized native Codex authentication and the intended repository context."], "scope": "The Python body is the unchanged upstream quickstart; the here-document is only its shell carrier. No SDK/provider/model execution or output-quality acceptance occurred.", "source": "https://github.com/openai/codex/blob/rust-v0.159.3/sdk/python/README.md#quickstart"} | sdk-source-review / 3 |
+| [Codex Python SDK](https://github.com/openai/codex) (`pypi:openai-codex`) | agent-sdks / picked | 0.160.0 / {"algorithm": "sha256", "kind": "artifact", "source": "https://pypi.org/pypi/openai-codex/0.160.0/json", "value": "61d2d855ca2ebedfd51280fbeb60ff31fc47ccbd55ebce186505e3f3da096921"} | {"command": "python -m pip install openai-codex==0.160.0", "execution_status": "UNRUN", "package_source": "https://pypi.org/pypi/openai-codex/0.160.0/json", "pinning_source": "https://pip.pypa.io/en/stable/cli/pip_install/", "scope": "Upstream package installed using pip documented module invocation and exact version syntax; run in the owned Python environment, never the OS Python.", "source": "https://github.com/openai/codex/blob/rust-v0.160.0/sdk/python/README.md"} | {"command": "python - <<'PY'\nfrom openai_codex import Codex\n\nwith Codex() as codex:\n thread = codex.thread_start()\n result = thread.run(\"Explain this repository in three bullets.\")\n print(result.final_response)\nPY", "evidence_class": "documented_upstream_example_not_executed", "execution_status": "UNRUN", "prerequisites": ["Owned Python environment with the selected SDK and its native CLI dependency installed.", "Existing authorized native Codex authentication and the intended repository context."], "scope": "The Python body is the unchanged upstream quickstart; the here-document is only its shell carrier. No SDK/provider/model execution or output-quality acceptance occurred.", "source": "https://github.com/openai/codex/blob/rust-v0.160.0/sdk/python/README.md#quickstart"} | sdk-source-review / 3 |
- claude verdict: pending; pending.
- codex verdict: pending; pending.
@@ -2101,7 +2101,7 @@ Reference edition: [catalogs/foundation/new-wsl-architecture-20261001.json](../c
| Repository source | SHA-256 |
| --- | --- |
| [adoption/manifest.json](../adoption/manifest.json) | `7bb179e8440be17b75484c21495e66385ea8eb959a491d43d2488056ddede09a` |
-| [adoption/new-wsl-profile.json](../adoption/new-wsl-profile.json) | `1e08ba8e879b0c52fd5c53341ea60bb27ca70ebc64cb9af655d9ba5ae0a21cb0` |
+| [adoption/new-wsl-profile.json](../adoption/new-wsl-profile.json) | `160d85512e237a2d2f65de752aed86dd1f4da8633fc77feb35324e7c4499d028` |
| [adoption/platforms/linux-wsl2-new-distro.md](../adoption/platforms/linux-wsl2-new-distro.md) | `7fdb79e02c0a2a670bc59e6ad86d4fe43132b93fb003763c1ce4e983505e23f4` |
| [catalogs/foundation/new-wsl-architecture-20261001.json](../catalogs/foundation/new-wsl-architecture-20261001.json) | `84c65a395145efe884a70b561205a3359b2b21022bd6fd4107d35d18016efdf6` |
| [catalogs/landscape/research-state.json](../catalogs/landscape/research-state.json) | `f47edec17a486e4e3de14bc2e3ef3a6224f3cf09b3830cb336b16bc6480050e1` |
diff --git a/evidence/artifacts/new-wsl-handbook-20261001/receipt.json b/evidence/artifacts/new-wsl-handbook-20261001/receipt.json
index 3c7b31a5a..cf5eccf4d 100644
--- a/evidence/artifacts/new-wsl-handbook-20261001/receipt.json
+++ b/evidence/artifacts/new-wsl-handbook-20261001/receipt.json
@@ -4,10 +4,10 @@
"source_main": "85543efe5abcddb7b7cddb14e8774e83b6758616",
"evidence_class": "local_integration",
"generator_sha256": "a78239b6a2558c916b30f4cbc852fe948904a849e99ae37cfadc1c810a6df20e",
- "profile_sha256": "1e08ba8e879b0c52fd5c53341ea60bb27ca70ebc64cb9af655d9ba5ae0a21cb0",
+ "profile_sha256": "160d85512e237a2d2f65de752aed86dd1f4da8633fc77feb35324e7c4499d028",
"outputs": {
- "docs/new-wsl-handbook.json": "c54dd6ff904dcd699798e87a4c374d47f6b83f2df93f24c3e60a73dfe54ee226",
- "docs/new-wsl-handbook.md": "c28e1c488cdc3e9e401ca65de69f61cbf15e22786404fac840a50fc823c96be3"
+ "docs/new-wsl-handbook.json": "93682c255f4cb4b06b250805b3529e155c7172e53e0387d97cacfd039fffa282",
+ "docs/new-wsl-handbook.md": "73fff09e4c2d193cd4b05d3e0ecde1fc45307c1214367d616c53e7ff0766b03e"
},
"inventory": {"layers": 37, "profile_entries": 69, "projected_tools": 73, "canonical_package_ids": 20},
"validation": [(c) Real CodexIntegrationTests against codex-cli 0.160.0 at a1a5488e
Binary. I downloaded the npm tarballs outside every repo and checked them against this PR's own pins. The host's production Codex install was not touched.
codex-0.160.0.tgz: sha256373517768e912eeb5054024ae9215e2c90a1420957b66fe134ef745a00948d4a.codex-0.160.0-linux-x64.tgz: sha25637a41d61c3399182b8c727b77090cc7a1566bd849d0f09070a0bbc6fec4c58dc.- Both equal
adoption/pins-linux-x86_64.json. - The extracted
vendor/x86_64-unknown-linux-musl/bin/codexhashes to12eb3e81114588aca3b7998f4f19e8997b056aca08e57a7ca7c8a3ec8c652aad, the pinnedinstalled_binary_check, and printscodex-cli 0.160.0. Thatbin/came first on PATH.
Command (2026-10-04T04:07:26Z to 04:09:04Z, TMPDIR under /var/tmp):
NAS_CODEX_INTEGRATION=1 nice -n 19 python3 -B -m unittest tests.test_codex_worker_lane.CodexIntegrationTests -v
Exit 0. Ran 10 tests in 98.146s, OK. All 10 ran, none skipped:
test_a_project_config_outranks_the_profile_but_not_the_pinned_flags: oktest_codex_follows_links_below_agents_and_the_role_count_never_undercounts_it: oktest_real_app_server_apply_and_byte_exact_rollback: oktest_strict_config_refuses_the_launchers_model_flag: oktest_strict_config_refuses_the_stack_worker_profile_at_this_pin: oktest_the_doctor_reader_accepts_the_shipped_roles_and_flags_a_malformed_one: oktest_the_jcodemunch_recipe_step_registers_the_server_only_where_it_is_copied: oktest_the_omniroute_filter_keeps_the_key_out_of_commands: oktest_the_omniroute_profile_loads_strictly_and_names_its_key: oktest_worker_profile_sets_chub_opt_outs_in_an_isolated_home: ok
By its own docstring, the test class needs no sign-in, gateway or network. It uses scratch Codex homes. It runs the gateway-profile tests and the dry run's rehearsal under bwrap --unshare-net when bwrap works. On this host, both of its isolation probes return a working bwrap --unshare-net wrapper: the class's isolation() command and apply_codex_lane.bwrap_wrapper.
(d) Exit codes on a1a5488e
TMPDIR was under /var/tmp and each command ran under nice -n 19. Each exit code was read directly, not through a pipe.
| Check | Exit |
|---|---|
python3 scripts/validate.py (194 receipts, 9,745 hashed files) |
0 |
python3 scripts/evidence_manifest.py --check (9,745 files) |
0 |
python3 scripts/validate_convergence.py --all-recorded --root . --json (29 records, all valid) |
0 |
python3 scripts/build_new_wsl_handbook.py --check |
0 |
python3 -m unittest tests.test_new_wsl_handbook (72 tests) |
0 |
python3 tools/adoption/new_wsl_client_config.py --check |
0 |
python3 blueprints/blind-catalog-convergence/audit_reports.py --check |
0 |
python3 tools/sota-convergence/build_verdicts.py --check |
0 |
python3 scripts/component_matrix.py --check |
0 |
python3 scripts/new_host_grand_list.py --check |
0 |
python3 tools/sota-convergence/gap_crosswalk.py build --check |
0 |
python3 tools/sota-convergence/gap_wave_ledger.py --wave gap-wave2-20260923 --wave gap-wave3-20260923 --owner gap-resolution --check |
0 |
python3 scripts/build_ecosystem.py --check |
0 |
python3 scripts/host_receipts.py validate (182 receipts) |
0 |
This PR's eight test modules, from git diff --name-only e7c297e2 HEAD -- tests/ (445 tests) |
0 |
tests.test_grand_dashboard, run because state.json changes (17 tests) |
0 |
git diff --check e7c297e2...HEAD |
0 |
Landing check merge_tree_landing_check.py e7c297e2 a1a5488e (conditions 1-5) |
0 (LANDABLE) |
The pre-push hook's three registry tests, in its own detached checkout of a1a5488e, during git push |
0 (push exit 0) |
The real CodexIntegrationTests in (c) |
0 |
The eight modules are:
test_adoption_bootstrap,test_adoption_bootstrap_linux_platform,test_adoption_bootstrap_macosandtest_adoption_bootstrap_parity;test_adoption_contractandtest_codex_worker_lane;test_new_wsl_profileandtest_render_config.
They skipped 42 tests:
- 32 in
test_adoption_bootstrap_macos: 17 need a real bash 3.2, 14 need PyYAML and 1 needs shellcheck; - the 10
CodexIntegrationTests, which needNAS_CODEX_INTEGRATION=1and ran in (c).
build_ecosystem.py --check passed. Its informational architecture_pin_drift lists two pins:
- seven codex rows, with edition pin 0.159.2 against stack pin 0.160.0;
- one nextjs row, with 16.3.6 against 16.3.8.
Main's own codex pin is 0.159.3, so the codex rows differ from main's pin as well.
The landing check against main e7c297e2 printed:
main e7c297e255c98337b54ff3d514191d5d1fa36354 head a1a5488e52c52ed2b1000d3d074e4efcad66d652 base e7c297e255c98337b54ff3d514191d5d1fa36354 merged-tree d7f79d231a79816c8311ad85c5759f4f4039d5f4 merge-tree-exit 0
ok 1: clean three-way merge
ok 2: merged-vs-main paths 88, outside PR-owned 0 []
ok 3: main drift 0 paths, overlap with PR-owned inputs (registry excluded) []
ok 4: registry foreign rows equal True, order preserved True, PR-owned rows 87, unowned top-level keys differing []
ok 5: merged files[] sorted by path with no duplicates: True (9745 rows)
LANDABLE
(e) Exact-head note
Acknowledgements given for 36d45155 name that head. Since then, the only content differences in this PR's own paths are the four listed in (a). The runtime receipt stays compatibility_attempt.
…wner's scope decision) The configuration owner moves the replacement-WSL profile and its Codex handbook rows in their own follow-up, so this PR no longer changes them: - adoption/new-wsl-profile.json and adoption/new-wsl-profile.md: restored to main's copies (e7c297e). - tests/test_new_wsl_profile.py: this PR's only hunk there, the 0.160.0 assertions for the profile's Codex CLI, accepted_codex_cli_pin and Python SDK pins, is reverted to main's lines. The file equals main's copy. - docs/new-wsl-handbook.{md,json}: regenerated with python3 scripts/build_new_wsl_handbook.py --write. With main's profile both equal main's copies. - evidence/artifacts/new-wsl-handbook-20261001/receipt.json: profile_sha256 and the two outputs hashes follow the restored profile and the regenerated files, so the receipt equals main's copy. - manifests/evidence.json: the six files re-registered with host_receipts.register_file. Their rows equal main's. This PR's receipts[] row runtime-sdk-20261003 stays, and convergence_records equals main's. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Refresh onto main fdd0a24 (#668 and #656, two commits after e7c297e) by the same method and the hot-file protocol (docs/lanes.md). Only manifests/evidence.json conflicted: - manifests/evidence.json: main's copy, with this branch's receipts[] row runtime-sdk-20261003 appended after main's last row. The two grand-list outputs are re-registered by new_host_grand_list.py --write (its --check passed first), and this branch's other 79 files by host_receipts.register_file from the merged tree. Main's 9,697 other rows are unchanged and in main's order, and convergence_records equals main's. - Main changed none of this branch's other paths, nor stack.json or state.json. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…on before the last commit Sets the three shared hot files (docs/lanes.md) to origin/main fdd0a24 so that the next and last commit carries this branch's whole hot-file delta against main. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…ile protocol, last commit) Against main fdd0a24: the Codex 0.160.0 pin and receipt list in manifests/stack.json; main's registry with this branch's rows and its runtime-sdk-20261003 receipt applied in manifests/evidence.json; and in observability/grand-dashboard/state.json the two Codex 0.160.0 gate rows beside main's gates, with main's checkpoint time and its meaning extended by one passage. The new-WSL profile, its test and the handbook are main's copies, so the registry carries no row of this branch for them. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
Dependency limit exceeded — report not shown. This pull request scan exceeded the 10,000-dependency limit applied to this scan, so the results are incomplete and may be inaccurate. To avoid reporting false positives, Socket has not posted a report. Upgrade your plan to raise the dependency limit and get complete reports, or view the partial scan in the dashboard. Socket is always free for open source. If this is a non-commercial open source project, contact us to request a free Team account. |
|
Claude session native-agent-stack-5f: head The configuration owner's decision.
Acknowledgements and ownership.
Commits. Pushed normally as
Main has since moved to (a) Scope proof,
|
| Check | Exit |
|---|---|
python3 scripts/validate.py (195 receipts, 9,778 hashed files) |
0 |
python3 scripts/evidence_manifest.py --check (9,778 files) |
0 |
python3 scripts/validate_convergence.py --all-recorded --root . --json (30 records, all valid) |
0 |
python3 scripts/build_new_wsl_handbook.py --check |
0 |
python3 -m unittest tests.test_new_wsl_handbook (72 tests) |
0 |
python3 -B -m unittest tests.test_new_wsl_profile, with main's profile and the 0.160.0 stack pin (17 tests) |
0 |
python3 tools/adoption/new_wsl_client_config.py --check |
0 |
python3 blueprints/blind-catalog-convergence/audit_reports.py --check |
0 |
python3 tools/sota-convergence/build_verdicts.py --check |
0 |
python3 scripts/component_matrix.py --check |
0 |
python3 scripts/new_host_grand_list.py --check |
0 |
python3 tools/sota-convergence/gap_crosswalk.py build --check |
0 |
python3 tools/sota-convergence/gap_wave_ledger.py --wave gap-wave2-20260923 --wave gap-wave3-20260923 --owner gap-resolution --check |
0 |
python3 scripts/build_ecosystem.py --check |
0 |
python3 scripts/host_receipts.py validate (182 receipts) |
0 |
This PR's seven test modules, from git diff --name-only fdd0a247 HEAD -- tests/ (428 tests) |
0 |
tests.test_grand_dashboard, run because state.json changes (17 tests) |
0 |
git diff --check fdd0a247...HEAD |
0 |
Landing check merge_tree_landing_check.py fdd0a247 0be2b134 (conditions 1-5) |
0 (LANDABLE) |
The pre-push hook's three registry tests, in its own detached checkout of 0be2b134, during git push |
0 (push exit 0) |
The seven modules skipped the same 42 tests as at a1a5488e:
- 32 in
test_adoption_bootstrap_macos; - the 10
CodexIntegrationTests; see (b).
build_ecosystem.py --check's informational architecture_pin_drift is unchanged: seven codex rows and one nextjs row.
The landing check against main fdd0a247 printed:
main fdd0a247aee96f21c4eff309bacdb3af322eb873 head 0be2b134f6ec605f9b65fef58867627aef6ef786 base fdd0a247aee96f21c4eff309bacdb3af322eb873 merged-tree 65389f4a9d8e05adcb925d00fd4d63ea4306a418 merge-tree-exit 0
ok 1: clean three-way merge
ok 2: merged-vs-main paths 82, outside PR-owned 0 []
ok 3: main drift 0 paths, overlap with PR-owned inputs (registry excluded) []
ok 4: registry foreign rows equal True, order preserved True, PR-owned rows 81, unowned top-level keys differing []
ok 5: merged files[] sorted by path with no duplicates: True (9778 rows)
LANDABLE
…egistry plus the owned rows) Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
… observability/grand-dashboard/state.json to the merge base before the final hot-file commit Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…servability/grand-dashboard/state.json edits on the merge base (hot-file protocol: every hot-file edit in the last commit) Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…egistry plus the owned rows) Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
… observability/grand-dashboard/state.json to the merge base before the final hot-file commit Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…servability/grand-dashboard/state.json edits on the merge base (hot-file protocol: every hot-file edit in the last commit) Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
Claude session native-agent-stack-5f: landing at head Observed main Required checks at this head: 8 pass . Unresolved review threads: 0. NativeStack host exception (dated 2026-10-04).
Basis:
Sessions:
Not in this PR: by the configuration owner's decision, the new-WSL profile and handbook stay at 0.159.3 here and move in that owner's follow-up. |
|
Claude session native-agent-stack-5f: post-merge observation. Landed as |
…ry; this branch's rows in the last commit) The merge brings main's #672, #626, #679 and #681. #681 (CI least privilege) rewrites 19 workflows (top-level permissions {}, job-level contents: read, cache-mode none on pull requests, concurrency groups) and adds tests/test_workflow_policy.py; CI's zizmor flags in validate.yml are unchanged. manifests/evidence.json is main's copy; the branch's rows are re-registered in the final commit. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…ocol) Brings #626 (Codex 0.159.3 -> 0.160.0, f77a35e), #679 and #681 (CI least privilege) under this branch. manifests/evidence.json is main's copy; the branch's rows are re-registered in the last commit. Conflicts resolved: - tools/adoption/apply_codex_lane.py: main's comment block and CODEX_VERSION = "0.160.0", followed by this branch's required-server constants unchanged. - tests/test_codex_worker_lane.py: this branch's version-free docstring line and skip reason (lane.CODEX_VERSION), which read 0.160.0 at main's pin. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…ck, addendum resolution) The pinned codex-cli 0.160.0 (adoption/pins-linux-x86_64.json, wrapper and linux-x64 tarballs matched by SHA-256 and SHA-512, vendored binary 12eb3e81...) ran in a scratch prefix; the host's default codex stayed 0.159.3. - CodexIntegrationTests: exit 0, Ran 12, OK (skipped=1, the opt-in trial). - The preregistered startup trial: exit 0; selection A holds (3/3 delayed starts expose Serena, 3/3 failed starts fail before any request). - Scratch checks (a) parse, (b) fail closed on a nonexistent command and (c) the real Serena transport the config template renders returned the same results under 0.160.0 and 0.159.3. (b) carries negative controls without required = true on the same nonexistent command: they get past MCP startup (a completed loopback turn, or the model call on the default provider with no credentials), while required = true exits 1 with only the required-server error, also when the provider requires auth. evidence/receipts/codex-serena-startup-port-20261003.json gains the dated rerun_0160_20261004 block (local_integration, no provider execution, no host apply) and two appended residual notes; residuals[8] (the driver's process-group kill) and [9] (a real --dry-run) stay open. The addendum gets a dated Resolution 2026-10-04 paragraph. No earlier text changed. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
… Opus 5.5 model (follow-up to #626) (#683) * New-WSL profile: Codex CLI and Python SDK pins 0.159.3 -> 0.160.0 after #626 PR #626 (merged at f77a35e, 2026-10-04T06:53:20Z) moved the shared Linux Codex pin and the openai-codex SDK pair to 0.160.0 and left the new-WSL profile, handbook and receipt for this follow-up. - adoption/new-wsl-profile.json: the Codex and Codex Python SDK rows and the boundary pins take the 0.160.0 values of #626's withdrawn profile commits (f51b3e0, fbbd939), each checked against main: npm tarball sha256 37351776... and 4,902 bytes (adoption/pins-linux-x86_64.json and the runtime-sdk-20261003 receipt), wheel sha256 61d2d855... (adoption/sdk/requirements-linux-x86_64-py313.lock), source commit a956835d (manifests/stack.json), published_at (runtime-sdk-20261003 qualification-facts.json) and the two rust-v0.160.0 release-asset digests (GitHub release API, read 2026-10-04). Both archives were downloaded and rehashed again on 2026-10-04. Provenance is #626's merged state on the #580 pattern: sdk_gate #626, sdk_gate_status merged_at_2026-10-04T06:53:20Z, accepted_main f77a35e. The TypeScript SDK row (#626 pinned no @openai/codex-sdk), source_head and the dated `codex update --help` observation stay. - adoption/new-wsl-profile.md: the overview sentences and the table follow. - tests/test_new_wsl_profile.py: #626's withdrawn hunk, verbatim (9bb0b1e^). - docs/new-wsl-handbook.{json,md}: python3 scripts/build_new_wsl_handbook.py --write, then --check (exit 0). - evidence/artifacts/new-wsl-handbook-20261001/receipt.json: profile_sha256 and the two outputs hashes follow the regenerated files (2026-10-01 handbook generator record, L665); generator_sha256 and the inventory are unchanged. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * New-WSL client config: main-checkout Codex trust grant and Opus 5.5 model Codex trust grant (coordinator's decision of 2026-10-04, R16 review: Codex 0.160.0's folder-trust dialog stays, our root pre-trusted, unknown projects still asked about; openai/codex #49160 is in rust-v0.160.0). - adoption/new-wsl/client-config-map.json: the shared template's existing projects."${PROJECT_ROOT}".trust_level piece gets its own entry, classed authorization, so it is rendered and written only with --with-authorization-settings and never over a file's own answer. ${PROJECT_ROOT} is the main checkout on the new distribution (host template), and Codex looks a linked worktree's trust up under it by exact key (rust-v0.160.0: tui/src/config_update.rs L264-279 and L305-366, git-utils/src/trust.rs L12-24, core/src/git_info_tests.rs L829-968, config/src/loader/mod.rs L131-133). The publication checkout and every other projects.* piece stay not wired. - tools/adoption/new_wsl_client_config.py: is_authorization_piece names codex/*/projects.*.trust_level (the one pattern the record's open observation asked for); the apply passes codex_home.py --keep-project-trust; the merge reports a piece whose key names a placeholder under the path the render filled (it reported such a grant as added even when the file had it); the default authorization line and the option's help name the grant. - tools/adoption/codex_home.py: additive --keep-project-trust, the mirror of --keep-hook-trust, so a new Codex home keeps the grant the render holds and a later merge ends with the same file. The bootstrap passes neither flag; its output is unchanged. Model: the user's choice of 2026-10-04 (question tool), Opus 5.5. A map entry overrides the shared template's opus[1m] with claude-opus-5-5 for the new distribution only (code.claude.com/docs/en/model-config, read 2026-10-04: the full model name pins a version; opus resolves to Opus 5.5 on the Anthropic API). The resolved model is the same as before; the new distribution no longer follows the shared template. No repository file held `sonnet` for it. - docs/decisions/2026-10-02-new-wsl-client-configuration.md: tables from --check --markdown, counts (385 / 293 / 79 / 13) and an addendum of 2026-10-04 with sources and overturn conditions. - tests: the authorization class gains the grant; new tests for a new Codex home with the option, a file's own answer kept, the predicate rows, the rendered model and codex_home's flag. Mutation controls: dropping the placeholder fill fails 4 tests, dropping --keep-project-trust fails 2. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * Register the new-WSL Codex 0.160.0 follow-up's files (hot-file protocol, last commit) host_receipts.register_file for the seven changed files main's manifests/evidence.json lists: adoption/new-wsl-profile.json and .md, docs/new-wsl-handbook.json and .md, the new-wsl-handbook-20261001 receipt, tests/test_bootstrap_full_profile.py and tests/test_new_wsl_profile.py. component_matrix.py --write and new_host_grand_list.py --write changed nothing. python3 scripts/validate.py: exit 0, status passed. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> --------- Co-authored-by: Scout <scout@local> Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
* fix(codex): require Serena before the worker's first turn Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * chore(evidence): register the Serena startup port Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * fix(codex): repair round on the Serena startup port after independent review Port #436's lane-home key-filter assertion and comment; record the driver's cleanup deviation, the control-profile hashes, the open model_reasoning_summary knob and the dated rebase resolution; cite mod.rs:4343-4346; document the dry run's required-serena read-back; reflow two broken sentences. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * chore(evidence): re-register the Serena startup port after the repair round Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * Codex lane: read back Serena's effective enabled and required; qualify the first-turn promise (P2 on #674) Codex waits only for MCP servers whose effective enabled and required are both true (openai/codex@a956835d, rust-v0.160.0: codex-rs/codex-mcp/src/connection_manager.rs:270-275), and a permitted cached start-up satisfies the wait without a live connection (connection_manager/required.rs:29-35). Both files are byte-identical at rust-v0.159.3. - apply_codex_lane.py: the read-back records Serena's effective enabled and disabled_reason (codex -p stack-worker mcp get --json, cli/src/mcp_cmd.rs: 970-983) and its effective required and startup_readiness, derived from config/read's layers plus the installed profile at precedence 21, because no command that takes --profile prints them (cli/src/main.rs:1861-1885). Validation fails on any recorded lookup error, on a missing read-back, and unless Serena is effectively enabled and required; an unreadable source reports "unknown" and fails. Existing checks are unchanged. - Template comment and recipe line: promise only what Codex guarantees, and name what lifts the wait (inherited enabled = false, project config, -c). The template stays TOML-equal. - Tests: SerenaReadbackTests (8 tests: inherited enabled = false, required missing, recorded lookup error, layer precedence, a failed config/read); failing first against the unchanged script (Ran 8, FAILED failures=14), passing after (Ran 8, OK). The fake codex now waits only for enabled required servers, can fail a named lookup, and can report extra layers. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * Registry: re-register the four files of the P2 repair (last commit, hot-file protocol) host_receipts.register_file for adoption/templates/codex.stack-worker.config.toml, recipes/README.md, tests/test_codex_worker_lane.py and tools/adoption/apply_codex_lane.py. component_matrix.py --write and new_host_grand_list.py --write changed nothing; validate.py and evidence_manifest.py --check pass (9,564 files). Only these four files[] rows changed; receipts[] and convergence_records[] are unchanged, and no convergence record pins a changed path. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * Worker-lane tests: emit arrays of tables in the fixture TOML writer After main's #659 the user template carries [[skills.config]], an array of tables. This PR's strict-config native test re-emits the rendered template through emit_toml to register a working fixture Serena, and the writer wrote the list as JSON objects, which Codex rejects ("Error loading config.toml", line 17 column 18); main's own copy of the test writes the rendered text directly, so the failure appeared only on the merge of main into this branch. The writer now emits a list of tables as [[...]] blocks after the table's key-value pairs. A structural guard round-trips the rendered user template and a nested case through emit_toml: failing first against the unchanged writer (Ran 1, FAILED errors=2), passing after (Ran 1, OK); the native test passes again against codex-cli 0.159.3 (Ran 1, OK). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * Registry: re-register the worker-lane tests after the fixture writer fix (last commit) host_receipts.register_file for tests/test_codex_worker_lane.py; the two --write generators changed nothing; validate.py and evidence_manifest.py --check pass (9,692 files). Only that files[] row changed. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * New-WSL client config: expectations for Serena's required key (B1, owner Option 2) The configuration owner approved updating the two expectations, not the code, and the coordinator ACKed it on 2026-10-04. With this branch's mcp_servers.serena.required = true merged, the checker counts one more piece, codex/stack-worker/mcp_servers.serena.required, wired through slot:serena. - docs/decisions/2026-10-02-new-wsl-client-configuration.md: Decision 2's counts become the measured (386, 294, 200, 94, 80, 41, 39, 12), and one dated 2026-10-04 sentence says why they moved. Decision 14's phrase quotes authorization 12 and 80 not wired, which did not move. - tests/test_new_wsl_client_config.py: the rendered stack-worker serena table is {"startup_timeout_sec": 60, "required": True}. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * Serena startup port: record the 0.160.0 rerun after #626 (receipt block, addendum resolution) The pinned codex-cli 0.160.0 (adoption/pins-linux-x86_64.json, wrapper and linux-x64 tarballs matched by SHA-256 and SHA-512, vendored binary 12eb3e81...) ran in a scratch prefix; the host's default codex stayed 0.159.3. - CodexIntegrationTests: exit 0, Ran 12, OK (skipped=1, the opt-in trial). - The preregistered startup trial: exit 0; selection A holds (3/3 delayed starts expose Serena, 3/3 failed starts fail before any request). - Scratch checks (a) parse, (b) fail closed on a nonexistent command and (c) the real Serena transport the config template renders returned the same results under 0.160.0 and 0.159.3. (b) carries negative controls without required = true on the same nonexistent command: they get past MCP startup (a completed loopback turn, or the model call on the default provider with no credentials), while required = true exits 1 with only the required-server error, also when the provider requires auth. evidence/receipts/codex-serena-startup-port-20261003.json gains the dated rerun_0160_20261004 block (local_integration, no provider execution, no host apply) and two appended residual notes; residuals[8] (the driver's process-group kill) and [9] (a real --dry-run) stay open. The addendum gets a dated Resolution 2026-10-04 paragraph. No earlier text changed. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * Registry: re-register the eight PR-owned files on main 6af8e55 (last commit, hot-file protocol) main's manifests/evidence.json (taken in the merge) plus register_file for the seven changed files main already lists and the new receipt. The other 9,871 rows and the receipts and convergence_records sections equal main's, in main's order. component_matrix.py --check and new_host_grand_list.py --check pass, so neither report needed --write. The two B1 files are not listed in main's manifest and are not registered. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * Registry: re-register the eight PR-owned files on main b629b5b (last commit, hot-file protocol) main's manifests/evidence.json (taken in the merge) plus register_file for the seven changed files main already lists and the new receipt. The other 9,874 rows and the receipts and convergence_records sections equal main's, in main's order. component_matrix.py --check and new_host_grand_list.py --check pass, so neither report needed --write. The two B1 files are not listed in main's manifest and are not registered. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> --------- Co-authored-by: Scout <scout@local> Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
… row, held status, TUI notice key (#687) * Codex dated holds (R6): one pin row with a host-agnostic 0.159.3 hold until 2026-11-04 - adoption/pins-linux-x86_64.json: the codex row carries holds[] with one entry, 0.159.3 until 2026-11-04 (X18, the #626 landing exception). Wrapper URL and SHA-256 are the row's values before f77a35e (from 85543ef, #580), re-verified against a registry download; the linux-x64 platform_dependency (row shape) is first recorded here from the npm registry. - scripts/adoption_status.py --pinned-versions: a probe naming a hold's version before its until date (UTC) is held (hold_* fields, summary "held", "held until <date> (<reason>)"), not drift; on and after until it is mismatched with the expiry stated. Malformed holds are skipped. The default run, the exit code and the existing keys are unchanged. - tools/adoption/apply_codex_lane.py still refuses any codex but CODEX_VERSION; the refusal now names a matching hold and its until date. - tests/test_pin_holds.py: every hold complete, until a real date after today (UTC) and at most 90 days away, at most one hold per row (the OSV ignoreUntil precedent), with mutants. - adoption/templates/codex.config.template.toml: "gpt-6.1-sol" = 4 under [tui.model_availability_nux], cited from openai/codex rust-v0.160.0 (MODEL_AVAILABILITY_NUX_MAX_SHOW_COUNT = 4). - docs/decisions/2026-10-04-codex-dated-holds.md: design, alternatives, precedent, overturn. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * Codex dated holds: stack.json reference and evidence registry (hot-file protocol, last commit) manifests/stack.json's codex row carries no install data, so its freshness refers to the pins row's dated hold instead of copying it. manifests/evidence.json takes main's copy (6af8e55) and re-registers this branch's changed files plus its new test and decision record, as #626 did; component_matrix.py and new_host_grand_list.py --write reproduced their outputs unchanged. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * New-WSL client-config record: recount after the gpt-6.1-sol notice key (387 pieces, 80 not wired, 39 own entry) The key under tui.model_availability_nux is one more not-wired piece (client state, not configuration). Recounted on the tree merged with main 54eb892 (#674, #683, #686) by the GPT-6.1 Sol worker; reviewed by the coordinator. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * Registry: re-register the PR-owned files after the recount (last commit) Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * Hot-file protocol: reset manifests/evidence.json to the merge base before the final hot-file commit Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * Reapply this branch's manifests/evidence.json edits on the merge base (hot-file protocol: every hot-file edit in the last commit) Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * adoption_status: one hold schema for run time and the pins test (cross-family P1) pin_holds() now keeps only holds that hold_schema_problems() accepts. The same validator is imported by tests/test_pin_holds.py. It requires the wrapper url and sha256, and the platform package's shape, version, url, digest and binary check when the pin has one. So a hold with malformed install metadata is ignored, and the version is reported as drift instead of held. Failing-first: the three missing-field cases failed before the fix; 16 malformed-metadata cases pass after it. Built by the GPT-6.1 Sol worker; reviewed by the coordinator (Claude Opus). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * Registry: re-register the fix's files (last commit) Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * Hot-file protocol: reset manifests/evidence.json manifests/stack.json to the merge base before the final hot-file commit Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * Reapply this branch's manifests/evidence.json manifests/stack.json edits on the merge base (hot-file protocol: every hot-file edit in the last commit) Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> --------- Co-authored-by: Scout <scout@local> Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
…ges 1-2, offline-tested) (#489) ### Scope This PR adds the host driver for the OpenHands issue-to-PR resolver on top of the merged #425 recipe. One explicitly scoped, owner-authored issue can produce one validated patch, one draft PR, one COMMENT review and one repair round. The model's patch is not executed on the host. A draft PR can execute it in GitHub CI under the resolver-mode amendment decided on 2026-10-04: option 1, with a trusted pre-push gate that checks every agent commit before any push (see "Pre-push gate" below). - **Base commit:** `d2fc3803e01178b4687771d0bf91faf453bb6933`, merged in `db24156b9` without rebasing or force-pushing. The original PR head `501bcc9e50bf3ffa3acc82b6ecf20aa4e23c593b` remains in history. Head: `7c1d24cc5600bed8b56435aef37ec8d267f889fe`. On top of `0f7b27578` it corrects this round's dates to 2026-10-04, as `date -u` gives them, in `b763cb294` (text only; the commit also resets the registry to main's copy), and re-registers the rows in `7c1d24cc5` (the last commit). On top of `4eb6b4cc9`, `0f7b27578` added the merge `4f963c9b2` of main `6af8e55bd` (#681, CI least privilege, with #672, #626 and #679). It also adds the gate fix that merge needed: the derivation follows code that gate code runs, not code it only reads (`GateReads.executed`), in `57d0dc065`. Main's #679 made `tools/adoption/install_claude_profile.py` read three workflow scripts, and following them had protected all of `blueprints/`. The decision record, `RESOLVER.md` and evidence part 8 are in `85262b1f8`, and the registry rows in `0f7b27578` (the last commit). The main-merge list below predates this merge. On top of `21b24dede`, `4eb6b4cc9` added the repair round for the cross-family read of `40f12ba5` (GPT-6.1 Sol, findings P1 and P2): the merge `db287ea72` of main `3bdacabd5`, the gate-data reader, the instruction fix and their tests in `86688e1e1`, the decision record, `RESOLVER.md` and evidence part 7 in `0092ae213`, the merge `4a03dd796` of main `ba0e8c48f`, the figures on that merge in `1ec9d04c3`, a receipt test and the final control runs in `e1b4f5c68`, and the registry rows in `4eb6b4cc9` (the last commit). Before that, on top of `050bca5d5`: the zizmor pin read from `.github/requirements-ci.txt` in `a5194090b` (registry `4009a96ec` and `40f12ba51`), then the CI-blocker round for CodeQL alert 90 and validate-macos (the merge `d1bb9cf15` of main `f474f6d22`, `36440d64a`, `9602c2274`, `8be0c1d39`, registry `21b24dede`). On top of `456f8fee6`, `050bca5d5` added the decided amendment's trusted pre-push gate: code and tests in `00905292d` and `48831bc65`, the decision record, `RESOLVER.md` and the evidence log in `868f02501`, and the registry rows in `050bca5d5`. Before that, on top of `b0c11c324`, came wording-only fixes for the [independent re-check](#issuecomment-5973091307) and the coordinator's follow-up: content in `f4e7aa2a2` and `54438ce7f`, registry rows in `d89ad3b44` and `456f8fee6`. This description was written for `b0c11c324`. Parts were updated for `050bca5d5`: the "Pre-push gate" bullet, the SOTA "Pre-push gate" line, the evidence rows and commands, the "Decision record" section and the decision item under "What is not done". For `4eb6b4cc9`, this line, the main merges, the owned paths, the "Pre-push gate" bullet and a SOTA "Gate data" line are updated; the evidence table and the commands still describe `050bca5d5`, and the later rounds' evidence is in `evidence/push-gate-fail-first.txt` parts 6 and 7 and the PR comments. The SOTA "Step 6 repair round" line was updated for `456f8fee6`. - **Main merges during custody.** Each followed the hot-file protocol: main's `manifests/evidence.json`, then this PR's owned rows re-registered. - `9b0b8d6d2` in `37cb51899`; - `4ced29230`, which carried main's `AGENTS.md` update, in `85830e815`; - `59f8a1e36` in `d35633fad`; - `d2fc3803e`, which contains `ecea28654`, in `db24156b9`; - `f474f6d22`, which carried main's macOS CI scope step (`e0c329ae9`), in `d1bb9cf15`; - `3bdacabd5` in `db287ea72`; - `ba0e8c48f`, which carried the OSV and SARIF hardening port, in `4a03dd796`. Main has since advanced to `b5b9c9ddb` (#672), which is not merged. Its 13 paths are jCodeMunch carrier files, documents, one test and evidence; none is a workflow or a gate script. The coordination merge-tree landing check of `4eb6b4cc9` against it reports LANDABLE: a clean three-way merge, 21 merged-vs-main paths and none outside the PR-owned set, no overlap with main's 13 drifted paths, the registry's foreign rows equal and in order, 20 PR-owned rows, and a sorted `files[]` without duplicates (9823 rows). - **Lane:** `lane:foundation`. - **Owned content paths:** `blueprints/runtime-workers/openhands/RESOLVER.md`, `resolver.py`, `resolver/{patch_policy,gh_harness,outgoing_guard,push_gate,gate_reads}.py`, `skills/resolver/SKILL.md`, `host.py`, `dispatch.py`, `worker.py`, `receipt.py`, `e2e/task.py`, both `evidence/stage2-*fail-first.txt` logs and `evidence/push-gate-fail-first.txt`, `docs/decisions/2026-09-28-openhands-resolver-isolation.md`, and the three OpenHands test modules (`tests/test_runtime_worker_openhands_push_gate.py` is new). The registry commits re-register these files over main's `manifests/evidence.json` and regenerate the four foundation reports through their supported commands. The last full pass is in the merge `db24156b9`. `b0c11c324` refreshes the rows of the three files that the step 6 repair round changed. `050bca5d5` refreshes the six rows the gate change touched and adds three new files' rows. `4eb6b4cc9` registers the 20 PR-owned files over main `ba0e8c48f`'s registry: 7 rows updated and 13 added, `resolver/gate_reads.py` among them. Both generators' `--check` passed each time, so no report was rewritten. - **Existing main defect disclosed.** Commits `0c9b7acf6` and `3e3877979` fix the SWE-bench skill contract and instruction. At the merged base, `host.py:382` requires `verification-before-completion` and `e2e/task.py:52` tells the worker to invoke it, while the runtime manifest lists that skill under `excluded`. The fix keeps the excluded skill out of both contracts and preserves the instruction to run and report the reproducing tests before finishing. - **Custody repair.** The alias-refusal fixture now builds all seven entries directly in a scratch Git index. It preserves case and decomposed Unicode names on filesystems that fold them, disables Git's macOS argument precomposition for those insertion commands, and exports the cached patch without restaging the worktree. All existing refusal assertions remain, with an added check that every intended name reached the validator. - **Review-round repair** (`2ede7b871`, tests only; its registry row in `b2d556c95`). The outgoing-guard fixtures no longer depend on `TMPDIR`. Two `host_path` assertions now use a synthetic absolute host root. The symlink case needs a real temporary root, so it probes that prerequisite. It skips with an explicit message when the root matches a `scripts/validate.py` `PRIVATE_CONTENT` pattern, such as a personal home path; the reason was reworded in `cf42c6d08`. No assertion or reason label changed. - **Step 6 repair round** (`cf42c6d08`: documentation and one test's comment and skip text; its registry rows in `b0c11c324`). - The decision record's option 2 and `RESOLVER.md` now state that the resolver pushes to and opens PRs only in this repository. A fork therefore needs a separately reviewed harness change before any run. - Both options now address condition 3 and CI egress. - The G4 residual gives the actual refusal order. - No behaviour changed. - **Pre-push gate** (the amendment's decision of 2026-10-04; content in `00905292d`, `48831bc65` and `868f02501`, registry in `050bca5d5`; the cross-family repair in `86688e1e1`, `0092ae213`, `1ec9d04c3` and `e1b4f5c68`, registry in `4eb6b4cc9`). - **Push path.** `GhHarness.push` runs `resolver/push_gate.py` on the exact agent commit before any push and pushes that commit by name (`<sha>:refs/heads/<branch>`, never `HEAD`). `GhHarness.run` refuses any push of a commit the gate did not pass, and any push without a gate. - **Refusals.** The gate diffs the commit against its base. It refuses, with no push, changes to `.github/**`, a `CODEOWNERS` anywhere, the resolver's gate and harness code, the workflow-policy tests (`tests/**.py` naming `.github`), and every file that a workflow reachable from the push or the PR executes or reads as a gate. That last list is derived from the workflow files by a text-level reader that reuses `patch_policy.names_in_text`: the files `run:` steps name, the import closure of the gate scripts, unittest discovery and local actions. It also refuses a step that interpolates untrusted event text. - **Gate data** (cross-family P1). The gate also refuses changes to the data those gate scripts read (`ci_read`, `resolver/gate_reads.py`), such as `blueprints/convergence-practice/contract.schema.json`, which `scripts/validate_convergence.py` reads. Each gate script's expressions are evaluated to the repository paths they spell. An exact path protects that file, and a computed one protects the directory or glob it resolves under. Code that gate code runs or reads is followed to a fixpoint. A read the reader cannot resolve refuses every commit (`gate_input_unresolved`) rather than protecting the whole tree; none is unresolved on the merged tree. The cost is breadth. The merged tree `4a03dd796` has 10,528 tracked files, and the gate protects 7,559 of them (441 before). Outside `evidence/`, `tests/` and `.github/` it protects 633 of 3,444 (122 before). Most of it comes from `tools/sota-convergence/gap_wave_ledger.py`'s computed `evidence/artifacts` and `docs/*.md` paths. The decision record's residual risks name the two deferred narrowings, and a repository test bounds the breadth. - **zizmor.** The gate runs the zizmor CI pins (1.30.1) with its own flags (no config, no ignores, offline). The excessive-permissions, dangerous-triggers, cache-poisoning, artipacked and template-injection audits refuse, and a missing or wrong zizmor fails closed. - **Trusted copy.** The gate runs only from the checkout it sits in, never from inside an agent tree. Its four files (`push_gate.py`, `patch_policy.py`, `gate_reads.py`, `gh_harness.py`) must equal the trusted commit's and the base's blobs, the trusted commit must be on main at the base, and the trusted commit is recorded. Each check leaves one record per commit in `resolver-outcome.json` (`push_gate`) and a code-and-count projection in the receipt. - **CLI.** `run` takes `--zizmor`, and the plan reports `push_gate: trusted_copy_checked`. - **Agent instructions** (cross-family P2). The resolver skill and the generated instruction name every category the gate refuses. When a fix would need such a change, including a new or changed test (`tests/**` is protected here), they tell the agent to stop and report instead of editing. A test keeps both in step with the gate's rules and the receipt's. The resolver's Stage 1 logic covers owner/edit provenance, a patch policy derived from the base's host-executed files, fixed `gh` templates, guarded outgoing text and a bounded PR loop. Stage 2 adds: - the same O1 containment topology; - fresh P0-P2 receipts and `stage-gates.json`; - G5 checks before container creation and at dispatch; - a pinned-main checkout with no MCP servers, and a fixed skill set; - a validated patch whose committed diff must match byte for byte. Its receipt does not infer successful completion from model-writable data. ### Independent review history 1. Stage 1 received a read-only GPT cross-family review (`gpt-6-astra`, max). Four findings were repaired, and a Claude closure review confirmed them closed: import shadowing, edited issue provenance, missing required contexts, and a review bound to a different commit. 2. Stage 2 received three independent Claude reviews. The verifier accepted with low notes; the security and design reviewers requested changes. The retained repair round addressed: - patch-content checking before `git apply`; - binding the G4 reviewer argv to a recorded hash; - retaining a PR record when GitHub holds the PR; - the residuals comment; - the receipt after a dispatch failure; - the excluded-skill instruction; - containment evidence; - fourteen smaller items. Both fail-first logs are unchanged: their blob SHAs at this head (`ed55377f`, `3f41c01b`) equal those at `501bcc9e`. 3. Stage 2's requested separate read-only GPT-6.1 Astra/max review through the packaged lane (custody contract step 6(a)) was pending at `b2d556c95`. It ran at `db24156b9` (job `rev-489-astra`) and returned **repair** with one should-fix finding, which `cf42c6d08` repairs (see "Step 6 reviews" and "Step 6 repair round"). The builder's diagnosis and tests do not count as that review. 4. The headless Opus 5.5 closure review of the whole repaired head (step 6(b)) was also pending at `b2d556c95`. It returned **repair** at `db24156b9`, with two should-fix and seven minor findings; "Step 6 repair round" gives each disposition. Before the PR leaves draft, the coordinator must still: - have the reviewers re-read this delta (contract step 6); - resolve every review thread; - confirm the required contexts on the final head. 5. A read-only Opus 5.5 custody review of `d35633fad` returned **repair**, with two should-fix and six minor findings. Their dispositions are under "Review round" below; reviews 3 and 4 cover the resulting head. ### Step 6 reviews (2026-10-03, head db24156b92ac) Items 3 and 4 of "Independent review history" and row 7 of "Review round" call these two reviews pending at `b2d556c95`; this section records their returned verdicts at `db24156b92ac`. Findings are condensed to one line each (severity, location, problem) without the reviews' fix proposals. Host paths are replaced by repository-relative paths or `<private path>`. Line numbers cited for the PR body are those of the body as read at 2026-10-03T19:20Z, before this section was added. **(a) GPT-6 Astra/max cross-family review**, run through the packaged lane, job `rev-489-astra`. Verdict: **repair**. One finding. - **should-fix** | `docs/decisions/2026-09-28-openhands-resolver-isolation.md:228-236`; `blueprints/runtime-workers/openhands/RESOLVER.md:535-537` | The fork option needs explicit implementation and safety prerequisites. The runbook permits proceeding after either choice, but `gh_harness.py:44-47,257-259,704-708` still targets the upstream repository and rejects a fork push URL, so following it after choosing a fork would use the same-repository path. Forking also leaves networked CI and final-message publication unresolved, while the unconditional token/secrets guarantee is explicitly unverified. **(b) Opus closure review.** Verdict: **repair**. Nine findings: two should-fix and seven minor. - **should-fix** | `docs/decisions/2026-09-28-openhands-resolver-isolation.md:227-236`; `blueprints/runtime-workers/openhands/RESOLVER.md:519-521` (also `:420-422`) | The fork option (option 2) is described incompletely, and `RESOLVER.md` files it under the wrong kind of change, so the owner cannot see what it costs or leaves open. (i) `RESOLVER.md:519-521` lists "pushing to an owner fork" among the "workflow changes outside this PR", but it changes this PR's own harness, which only targets this repository (`gh_harness.py:44`, `:241-254`, `:257-259`, `:448`, `:627-628`, `:684-689`, `:704-709`; the record's ruleset section, `:131-178`, binds only this repository's `openhands/*` refs), so option 2 needs harness changes, a ruleset on the fork and its own review before any run, while option 1 needs no code change. (ii) Option 2 (`:230-232`) says nothing about condition 3: `build_pr_body` (`resolver.py:547-550`, `:590-592`) publishes up to 6000 characters of the agent's final message wherever the branch lives, so option 2 leaves that deviation open while option 1 explicitly accepts it, and the record's closing sentence (`:235-236`) implies that accepting either option lets the first live run go ahead. (iii) The fork's owner is not named (the repository is public and owned by a User account; isFork false, forkCount 0), and the record already says GitHub's fork-PR limits were not re-read. - **should-fix** | PR #489 body (`gh pr view 489 --json body`, read 2026-10-03T19:20Z): lines 5, 6, 8, 46, 52, 149 ("CI on this head"), 151 | The body still describes `b2d556c95`, not the reviewed head `db24156b9`: line 5 (base and head); line 6 (main `ecea2865` "not merged", and the merge list omits `db24156b9`, which merges main `d2fc3803e`, already containing `ecea28654`); line 8 (last full registry pass `d35633fad`); lines 46 and 151 (`d35633fad` as the Linux full-suite evidence, "differs from this head only in the repaired test module"); line 52 and the "CI on this head" paragraph, line 149 (`validate` failed on main's unsorted registry pair). At `db24156b9` the registry has 0 unsorted pairs and `validate` passed: job `111264954786` (head_sha `db24156b9`, CI merge `69650a33` onto `d2fc3803e`) shows `validate.py` `{"hashed_files": 9550, "receipts": 193, "status": "passed"}`, `component_matrix.py --check` `{"rows": 32, "status": "checked"}`, the new-host grand-list check passed, and `python3 -m unittest` "Ran 10078 tests ... OK (skipped=968)". Contract step 8 requires the merged main SHA, the local commands with exit codes and an evidence table for the head that lands. - **minor** | `tests/test_runtime_worker_openhands_resolver.py:1582-1589` | The probe and the assertions are correct; only the skip message is too narrow. The probe string `f"{self.tmp}/"` (`:1584`) fires exactly when the guard (`outgoing_guard.py:165-170`) would refuse as `private_content` before `host_path`, and no assertion is weakened (`host_path` is still asserted at `:1565` on the synthetic root, the ValueError cases moved unchanged to `:1570-1573` ahead of the skip, and the symlink and realpath assertions at `:1590-1592` are unchanged). The skip message (`:1588-1589`) and the comment (`:1582`) blame "TMPDIR is under a personal home path", but the probe fires on any `scripts/validate.py` `PRIVATE_CONTENT` pattern (`validate.py:25-37`), such as a session-UUID, task-handle or Windows-user-path `TMPDIR`, and then the skip names the wrong cause. - **minor** | PR #489 body line 175; `blueprints/runtime-workers/openhands/RESOLVER.md:514-516`; order at `blueprints/runtime-workers/openhands/resolver.py:1589-1591` and `host.py:1359-1361` | The body says "G4 remains unrecorded, so a real run refuses with `stage_gate_g4_not_recorded`", but that reason code applies only once the other gates are recorded. Today there is no `<state>/stage-gates.json`: `plan_run` calls `host.verify_stage_gates` first (`resolver.py:1589`), and `read_stage_gates` raises `stage_gates_not_recorded` (`host.py:1360-1361`) before `verify_reviewer_gate` (`resolver.py:1591`) can raise `stage_gate_g4_not_recorded`. The gates themselves are intact: no bypass flag or environment override exists, `_cmd_run` requires `--reviewer-command` (`resolver.py:1663-1664`), and at dispatch start `verify_isolation` (`dispatch.py:319`) re-checks P0-P2 freshness (`host.py:1445-1447`), the stage gates and G5 (`host.py:1463-1464`). - **minor** | Required context `validate-macos` on `db24156b9` (run `37144290967`, job `111264957003`) | Verification gap, not a defect: `validate-macos` was still pending (queued) at 2026-10-03T19:20:37Z; the other seven required contexts passed on `db24156b9`. The native-macOS evidence the review read is from the earlier head `d35633fad` (artifact `11278304065` of run `37129286224`, `full-suite-macos.log`: "Ran 10070 tests ... OK (skipped=1329)", `test_case_unicode_and_filesystem_aliases_are_refused ... ok`, no FAIL or ERROR in `tests.test_runtime_worker_openhands_resolver`). That confirms the git-plumbing alias fixture on APFS but predates the `TMPDIR` repair `2ede7b871`; the `db24156b9` run is the first native-macOS run of that repair. - **minor** | Contract step 6(a) (`<private path>:71`); PR #489 review state | Verification gap, not a defect: the separate read-only GPT-6.1 Astra/max cross-family review was still pending when this review ran; GraphQL at 19:20Z showed 0 review threads and 0 reviews on the PR. - **minor** | `origin/main` `1f5a791b02a230aced670c88bab3d3d0ebcf401a` versus the merged base `d2fc3803e01178b4687771d0bf91faf453bb6933`; `manifests/evidence.json` | Verification gap, not a defect: main moved after the custody merge (#640, #648). Three registry rows changed: `docs/harness-defaults.md`, `observability/grand-dashboard/state.json` and `docs/token-session-handbook.md`. Their hunks do not overlap this PR's `evidence.json` hunks, but the landing head no longer merges current main. - **minor** | Contract step 5 commands at `db24156b9` | Verification gap, not a defect: the review ran no acceptance command (it had no Bash; those are the coordinator's commands). Not re-run at `db24156b9`: the unit-test pair under a neutral `TMPDIR` and a home-path `TMPDIR`, the planted-defect mutations, `resolver.py --help` and `run --help`, `git diff --check` and the pre-push gitleaks scan. The body records them only at `b2d556c95`. CI on `db24156b9` covers the Linux full suite, `validate.py`, the generator checks and secret-scan. - **minor** | Items 3-4 and the safety boundary, verified at `db24156b9` | No defect (verification record). Scope: `d2fc3803e..db24156b9` is exactly the 17 allowed paths (`README.md`, `.github/` and `blueprints/us-equities/` untouched; owned files equal `b2d556c95`). Hot-file merge: all 9541 rows of main's `evidence.json` kept in order, 9 new and 7 updated owned rows added, all 16 sha256/bytes values match HEAD, `receipts[]` and `convergence_records[]` equal main's, `files[]` sorted with no duplicates. Preserved: both fail-first blobs (`ed55377f`, `3f41c01b`), decision-record lines 1-15 (match `501bcc9e` and main), the amendment heading at `:208`, the skill-contract fix (`host.py:408-413`, `e2e/task.py:46-56`) and the A7 env-name read in teardown (`host.py:1095`). At the merged base the 11 `pull_request` workflows still declare `contents: read` and use no secrets, and the SARIF upload jobs still skip `pull_request`. `fold()`, `HFS_IGNORABLE` and the alias rules (`patch_policy.py:116-129`, `:893-897`, `:953-958`) decide from git data, and the outgoing guard's check order and 0600 `O_EXCL|O_NOFOLLOW` body files are intact. ### SOTA sources - [git/git `v2.43.0`](https://github.com/git/git/tree/v2.43.0), matching installed Git 2.43.0: [the native index-fixture reference](https://github.com/git/git/blob/v2.43.0/t/t2107-update-index-basic.sh#L59), [git-hash-object(1)](https://github.com/git/git/blob/v2.43.0/Documentation/git-hash-object.txt#L18), [git-update-index(1)](https://github.com/git/git/blob/v2.43.0/Documentation/git-update-index.txt#L75), and [index insertion implementation](https://github.com/git/git/blob/v2.43.0/builtin/update-index.c#L421). The additional macOS requirement follows [git.c's argument conversion](https://github.com/git/git/blob/v2.43.0/git.c#L449), [precompose_utf8.c](https://github.com/git/git/blob/v2.43.0/compat/precompose_utf8.c#L67), and [core.precomposeUnicode](https://github.com/git/git/blob/v2.43.0/Documentation/config/core.txt#L44). Installed help, versioned release notes and these primary sources were read on 2026-10-03. Earlier resolver patch handling also follows `git-apply(1)`, `git-diff(1)` and `git-merge-base(1)` at this revision. - [Gitleaks `v8.30.1`](https://github.com/gitleaks/gitleaks/tree/v8.30.1): [release notes](https://github.com/gitleaks/gitleaks/releases/tag/v8.30.1), [native Git-range and directory commands](https://github.com/gitleaks/gitleaks/blob/v8.30.1/README.md#L196), and installed CLI help. The sandbox tests select the same installed upstream binary directly because the host wrapper's lock directory is outside the writable sandbox. - Existing resolver implementation references: [OpenHands/extensions `bea7a20`](https://github.com/OpenHands/extensions/tree/bea7a20), `skills/github-issue-to-pr/scripts/main.py` (branch naming and loop) and `skills/github-pr-reviewer/scripts/worker.py`; [OpenHands/software-agent-sdk `fcc102a`](https://github.com/OpenHands/software-agent-sdk/tree/fcc102a), v1.49.6; [OpenHands/OpenHands `7bc33009`](https://github.com/OpenHands/OpenHands/tree/7bc33009), the retired resolver comparison. These are the original implementation's historical reviewed pins; the custody change adds no runtime or orchestration alternative. - [cli/cli `v2.101.0`](https://github.com/cli/cli/tree/v2.101.0) (`0cf10924`), including `pkg/cmd/pr/checks/aggregate.go`, credential-helper behavior and fixed `api`/PR operations; [GitHub create-review documentation](https://docs.github.com/en/rest/pulls/reviews#create-a-review-for-a-pull-request) (`commit_id`) and [GraphQL issue/edit provenance](https://docs.github.com/en/graphql/reference/objects#issue), read in the original 2026-09-28/29 implementation review; CPython `v3.12.3`, `importlib._bootstrap_external.FileFinder`, for package-before-module resolution. - Repository: `docs/decisions/2026-09-28-openhands-resolver-isolation.md`, `docs/lanes.md`, `.github/pull_request_template.md`, the merged #425 recipe, #429's runtime skill exclusion and #465's agent-branch ruleset. The registry follows the hot-file protocol: main's copy at each merge, then `scripts/host_receipts.py:register_file` for the owned rows and the supported report generators. - Review-round fixture repair: [git/git `v2.43.0` `t/test-lib-functions.sh`](https://github.com/git/git/blob/v2.43.0/t/test-lib-functions.sh#L750) (`test_lazy_prereq`, a probed prerequisite; filesystem examples such as `SYMLINKS` and `CASE_INSENSITIVE_FS` in [`t/test-lib.sh`](https://github.com/git/git/blob/v2.43.0/t/test-lib.sh#L1773)), and [CPython `v3.13.15` `Lib/unittest/case.py`](https://github.com/python/cpython/blob/v3.13.15/Lib/unittest/case.py#L54) (`_Outcome.testPartExecutor` records a `SkipTest` raised inside `subTest` as that subtest's skip; `subTest`, `:538-565`, resumes after the block and stops the method under failfast). Read on 2026-10-03; the installed interpreter's `case.py` is byte-identical to that tag. - Step 6 repair round: repository source read at `b0c11c324`, covering `resolver/gh_harness.py` (`REPO`, `op_push`, `push`, `op_pr_create` and its allowlist entry, `check_repository` and `branch_rules`), `resolver.py` `build_pr_body` and `plan_run`, and `host.py` `read_stage_gates`. The repository's owner type, visibility and fork count were read with `gh api` on 2026-10-03. GitHub's fork-PR token and secret limits come from [Events that trigger workflows, "Workflows in forked repositories"](https://docs.github.com/en/actions/reference/workflows-and-actions/events-that-trigger-workflows), for `pull_request` runs from a fork. [Forks, "Which repositories can be forked?"](https://docs.github.com/en/pull-requests/reference/forks) says nothing on forking one's own repository, so the decision record marks the fork's holder undetermined. Both pages were read 2026-10-03 and re-read 2026-10-04T00:23Z. - Pre-push gate (2026-10-04). The GPT-family job 004's six sources, which also cover the command center's proposal, were each fetched on 2026-10-04 (HTTP 200) and quoted in the decision record: - [GitHub Secure use reference](https://docs.github.com/en/actions/reference/security/secure-use): "Any user with write access to your repository has read access to all secrets configured in your repository", plus untrusted checkout and hosted runners; - [Workflow syntax](https://docs.github.com/en/actions/reference/workflows-and-actions/workflow-syntax): unspecified permissions are set to none, `cache-mode`, `steps[*].run`, `working-directory` and local `uses: ./`; - [Events that trigger workflows](https://docs.github.com/en/actions/reference/workflows-and-actions/events-that-trigger-workflows): `push` "includes workflows that are not merged into the default branch", and the fork limits; - [Dependency caching reference](https://docs.github.com/en/actions/reference/workflows-and-actions/dependency-caching): PR runs restore base and default-branch caches, and their own caches are scoped to the merge ref; - [OpenSSF Scorecard checks](https://github.com/ossf/scorecard/blob/main/docs/checks.md): Token-Permissions and Dangerous-Workflow; - [zizmor audits](https://docs.zizmor.sh/audits/): the five audits the gate fails on, each working offline. The gate's mechanisms add three more: [GitHub Script injections](https://docs.github.com/en/actions/concepts/security/script-injections) (the untrusted-context endings), [Python unittest, "Test Discovery"](https://docs.python.org/3/library/unittest.html#test-discovery) with the installed CPython 3.13.15 `unittest/loader.py`, and the installed zizmor 1.30.1 `--help`. In-repository references: `patch_policy.py`'s reviewed derivation, `tests/test_workflow_hardening.py`'s text-level workflow reading, and `.github/requirements-ci.txt` and `validate.yml` for CI's zizmor pin and flags. - Gate data (cross-family repair, 2026-10-04). The Python behaviour the reader models, from docs.python.org/3.13 (read 2026-10-04, HTTP 200) and checked on the installed CPython 3.13.15: [pathlib](https://docs.python.org/3.13/library/pathlib.html) ("If a segment is an absolute path, all previous segments are ignored (like os.path.join())"; `Path.rglob`), [fnmatch](https://docs.python.org/3.13/library/fnmatch.html) ("the filename separator ('/' on Unix) is not special to this module"), [tomllib](https://docs.python.org/3.13/library/tomllib.html) and [csv](https://docs.python.org/3.13/library/csv.html) (read through a file object), and the comprehension scopes of the [Language Reference 6.2.4](https://docs.python.org/3.13/reference/expressions.html#displays-for-lists-sets-and-dictionaries) and [PEP 572](https://peps.python.org/pep-0572/). In-repository: `scripts/validate_convergence.py` (P1's example) and `tools/sota-convergence/gap_wave_ledger.py` (the main source of breadth). ### Evidence-class table | Claim | Evidence class | Command / receipt | | --- | --- | --- | | Resolver templates, patch policy, outgoing guard, PR loop, host mode and end-to-end fake scenarios | `local_integration` | Required OpenHands test pair at `b0c11c324` with a neutral `TMPDIR`: 248 tests, exit 0. It uses fake Docker, GitHub and agent-server operations and real local Git | | The pair no longer depends on `TMPDIR` | `local_integration` | The same pair at `b0c11c324` with a throwaway `TMPDIR` under the host's home path: exit 0, `OK (skipped=2)`. The two symlink subtests are skipped by the probed prerequisite with the reworded reason. At `d35633fad` the same run exited 1 with failures=2 (`'private_content' != 'host_path'`) | | The repaired guard assertions still catch planted defects | `synthetic`, at `2ede7b871` | Scratch worktree at `2ede7b871`. With the `host_path` refusal disabled, both tests fail under both `TMPDIR`s (exit 1). With the realpath form dropped, the symlink subtest fails under a neutral `TMPDIR` (exit 1) and is skipped under a home-path `TMPDIR`. Not re-run at `b0c11c324`: `cf42c6d08` changes only that test's comment and skip text, not an assertion | | The previous alias fixture fails when its three names collapse | `synthetic` | Existing unittest with only the three alias writes remapped: three matching failed assertions, exit 1 before repair; exit 0 after repair | | All seven alias paths reach the unchanged validator and retain every refusal check | `local_integration` | All 11 `PatchValidatorTests` inside the pair run at `b0c11c324`, exit 0 on Linux with real Git 2.43.0; no platform skip | | The repaired alias fixture and the `TMPDIR` repair pass on native macOS | `source_review` of retained CI execution output | `db24156b9`: `validate-macos` job `111264957003` (run `37144290967`), artifact `full-suite-macos.log`: `Ran 10078 tests`, `OK (skipped=1329)`, no FAIL or ERROR block. `test_case_unicode_and_filesystem_aliases_are_refused`, `test_host_paths_and_the_user_name_are_refused` and `test_pr_body_follows_the_template_and_renders_model_text_inert` are each `ok`. This is the first native macOS run of `2ede7b871`. Earlier, `d35633fad`'s job `111220987307` passed the alias test. `b0c11c324`: pending | | The old native macOS suite failed at exactly the three alias subtests | `source_review` of retained historical execution output | Run `36524134513` (head `501bcc9e`), job `109263298833`, artifact `11015337319`, `full-suite-macos.log`: 7339 tests, failures=3, skipped=959. Its three FAIL blocks are the subtests `docs/A.md`, `Docs/z.md` and `docs/café.md` at test line 725, each `('case_or_unicode_alias', path) not found`. Re-downloaded read-only in the custody review round | | The original tests catch planted defects | `synthetic`, historical | 9 of 9 repair-round mutations detected; unchanged `evidence/stage2-*fail-first.txt` logs | | Git's macOS argument precomposition needs an explicit fixture override | `source_review` | git/git `v2.43.0` `git.c:449`, `compat/precompose_utf8.c:67-105`, `Documentation/config/core.txt:44-51` | | The resolver as built pushes to and opens PRs only in this repository, so the fork option needs a harness change | `source_review` | At `b0c11c324`: `resolver/gh_harness.py:44`, `:241-254`, `:257-259`, `:448`, `:627-628`, `:684-689`, `:704-709`; the final message reaches the PR body through `resolver.py:547-550`, `:590-592` | | A real run refuses at the gates stage before G4 today | `source_review` | At `b0c11c324`: `plan_run` checks the stage gates, G5 and then G4 (`resolver.py:1589-1591`). `read_stage_gates` raises `stage_gates_not_recorded` when `stage-gates.json` is absent (`host.py:1357-1361`) | | The original workflow/token bounds | `source_review`, historical scope | Stage 2 security review of 20 workflows at `94894f54`; this is not current-base CI or fork acceptance | | Linux full suite in CI | `source_review` of retained CI execution output | `db24156b9`: `validate` job `111264954786`, CI merge `69650a33` of `db24156b9` into `d2fc3803e`, `python3 -m unittest`: `Ran 10078 tests in 1664.615s`, `OK (skipped=968)`. `b0c11c324`: pending | | Linux full suite on the host | `local_integration`, before the step 6 round | Registry commit `96b96c681` (only `.github/workflows/validate.yml` and `manifests/evidence.json` differ at `d35633fad`), home-path `TMPDIR`: exit 1; 10,070 tests, failures=12, errors=1, skipped=850. Its 13 failing IDs are the 2 fixture cases repaired in `2ede7b871` and the 11 compared in the next row. Not re-run at `b0c11c324`: it takes about 43 minutes on this host, which would overrun a scheduled measurement window. The builder's sandbox run (10,046 tests, 485 failures) is superseded | | None of the 11 remaining IDs is specific to this PR | `local_integration`, at `b2d556c95` | Same command and `TMPDIR` at `b2d556c95`, in a fresh detached worktree at origin/main `ecea2865`, and at the then-merged base `59f8a1e36`. With a neutral `TMPDIR`, the same 1 failure on every tree; with a home-path `TMPDIR`, the same 9 failures on every tree. Supersedes the builder's 607-method archive comparison and the earlier `4ced2923` clone control | | Publication validation | `local_integration` | `scripts/validate.py` with a neutral `TMPDIR` at `b0c11c324`: exit 0, `"status": "passed"` (9,550 hashed files, 193 receipts). CI's `validate.py` passed on `db24156b9` (job `111264954786`). The builder's exit 1 (the `AGENTS.md` mismatch before the `4ced2923` merge) is superseded | | Registry rebuild and generated reports | `local_integration` | At `db24156b9`: all 16 owned rows over main `d2fc3803e`'s registry. At `b0c11c324`: the rows of the record, `RESOLVER.md` and the resolver test module are refreshed. Both generators exit 0 and change no file, and `scripts/evidence_manifest.py --check` passes (9,550 files) | | Configured Gitleaks scan of history | `local_integration` | Gitleaks 8.30.1 over `origin/main..HEAD` at `b0c11c324`: 36 commits, exit 0, no leaks found. The pre-commit scans of both step 6 commits found no leaks | | Required contexts on the pushed head | `source_review` of CI status | `db24156b9`: all eight passed (`validate` job `111264954786`, `validate-macos` job `111264957003`). A later `validate` re-run there (job `111278594671`) was cancelled at 19:56:39Z, after `b0c11c324` was pushed. `b0c11c324` at 19:58:50Z: dependency-review, osv-scanner, sota-sources, token-report and verdict-review-gate passed; validate and secret-scan were in progress; validate-macos was queued | | The pre-push gate refuses planted protected changes before any push, passes a benign commit, refuses from inside the agent tree and fails closed without zizmor | `local_integration` | `tests.test_runtime_worker_openhands_push_gate` at `050bca5d5`: 31 tests, exit 0, `OK (skipped=1)`, the PyYAML cross-check, which this interpreter cannot run; its real-zizmor 1.30.1 test ran | | The gate's workflow reader matches PyYAML on all 21 workflows | `local_integration` | `/usr/bin/python3` (PyYAML 6.0.1) `-m unittest ...push_gate.RepositoryWorkflowTests`: 3 tests, exit 0 | | The new and updated tests fail without the gate | `synthetic`, failing-first | Base `456f8fee6` with the new tests copied in: gate module exit 1 (errors=7), resolver module exit 1 (failures=1, errors=56), each traced to the missing gate API (`evidence/push-gate-fail-first.txt`, part 1) | | The gate's tests catch planted defects | `synthetic` | 17 mutations of `push_gate.py` and `gh_harness.py`, each failing its named tests (exit 1); the unmutated copy passes (part 2) | | The gate on this repository's own trees, with real zizmor | `local_integration`, rehearsal | Local clones of `48831bc65` with one planted commit each, real zizmor 1.30.1, no resolver, container or GitHub call. The benign edit passes. Workflow, CODEOWNERS, gate-script, helper, policy-test, new-test, `.gitleaks.toml` and gate-code edits are refused with their rules, and a planted template injection is refused by zizmor. About 2 s per check (part 4) | | Live resolver containment, model/gateway behavior, GitHub writes | not run / not accepted | The CI posture is decided (option 1 with the trusted pre-push gate). The first live run waits until the gate lands on main, its negative controls pass there, and G2/P3/G5 and G4 are recorded with fresh P0-P2. No live resolver run occurred | ### Local commands run ```text # Head 050bca5d5 (pre-push gate), 2026-10-04 04:00-04:02Z. TMPDIR=/var/tmp/489-gate, nice -n 19, after # git fetch origin main (origin/main aecfaaaa6, merge base d2fc3803e). The tree was clean at this head. $ python3 -m unittest tests.test_runtime_worker_openhands_resolver tests.test_runtime_worker_openhands exit 0; Ran 249 tests in 20.319s; OK $ python3 -m unittest -v tests.test_runtime_worker_openhands_push_gate exit 0; Ran 31 tests in 8.958s; OK (skipped=1: the PyYAML cross-check; the real-zizmor test ran) $ /usr/bin/python3 -m unittest tests.test_runtime_worker_openhands_push_gate.RepositoryWorkflowTests exit 0; Ran 3 tests; OK (PyYAML 6.0.1 cross-check of the workflow reader) $ python3 scripts/validate.py exit 0; {"components": 69, "hashed_files": 9553, "profiles": 4, "receipts": 193, "status": "passed"} $ python3 scripts/evidence_manifest.py --check exit 0; {"files": 9553, "status": "passed"} $ python3 scripts/component_matrix.py --check; python3 scripts/new_host_grand_list.py --check # before the registry commit exit 0 {"rows": 32, "status": "checked"}; exit 0 {"status": "passed", "layers": 32, "winners": 66}; no --write needed $ git diff --check origin/main...HEAD exit 0 $ python3 blueprints/runtime-workers/openhands/resolver.py --help; ... run --help exit 0; exit 0 (run --help lists --zizmor) $ gitleaks git . --config .gitleaks.toml --log-opts=origin/main..HEAD --redact --timeout 600 exit 0; 44 commits scanned; no leaks found (the four commits' pre-commit scans: no leaks) $ python3 <the coordinator's merge-tree landing check> aecfaaaa6 050bca5d5 exit 0; clean three-way merge; merged-vs-main paths 20, outside PR-owned 0; main drift 304 paths, overlap 0; registry foreign rows equal, order preserved, PR-owned rows 19; merged files[] sorted, no duplicates (9735 rows); LANDABLE $ git push origin HEAD:claude/openhands-resolver-20260928 exit 0; pre-push registry tests: Ran 3 tests, OK; 456f8fee6..050bca5d5, no force Failing-first, planted-defect and rehearsal runs: blueprints/runtime-workers/openhands/evidence/push-gate-fail-first.txt. Not run: the host full suite (about 43 minutes here); CI runs it on the pushed head. # Head b0c11c324 (step 6 repair round), 2026-10-03 19:53-19:56Z. TMPDIR is a neutral # directory outside the home directory and every repository, unless the line says # home-path TMPDIR. The commands ran on the working tree, which was then committed # unchanged as cf42c6d08 and b0c11c324. $ git diff --check exit 0 $ nice -n 19 python3 -c '<host_receipts.register_file(Path("."), p) for each path>' <the record> <RESOLVER.md> <the resolver test module> exit 0 $ nice -n 19 python3 scripts/component_matrix.py --write exit 0; {"flip_rule_violations": 0, "rows": 32, "status": "written"}; no file changed $ nice -n 19 python3 scripts/new_host_grand_list.py --write exit 0; {"status": "written", "layers": 32, "winners": 66}; no file changed $ nice -n 19 python3 scripts/evidence_manifest.py --check exit 0; {"files": 9550, "status": "passed"} $ nice -n 19 python3 scripts/validate.py exit 0; {"components": 69, "hashed_files": 9550, "profiles": 4, "receipts": 193, "status": "passed"} $ nice -n 19 python3 -m unittest tests.test_runtime_worker_openhands_resolver tests.test_runtime_worker_openhands exit 0; Ran 248 tests in 22.014s; OK $ (home-path TMPDIR, a throwaway directory removed afterwards) nice -n 19 python3 -m unittest -v <the same pair> exit 0; Ran 248 tests in 24.993s; OK (skipped=2); both skips give the reworded reason $ nice -n 19 python3 blueprints/runtime-workers/openhands/resolver.py --help exit 0 $ nice -n 19 python3 blueprints/runtime-workers/openhands/resolver.py run --help exit 0 $ nice -n 19 git diff --check origin/main...HEAD exit 0 (origin/main 463a57b98, merge base d2fc3803e); git diff --name-only origin/main...HEAD: the 17 contract paths $ cmp <(git show 501bcc9e:<record> | sed -n 1,15p) <(sed -n 1,15p <record>) # and the same against origin/main exit 0; exit 0 $ git rev-parse HEAD:<log> 501bcc9e:<log> # both evidence/stage2-*fail-first.txt logs ed55377f232aa64f46f1b7dce004fce1be5cc7a7 and 3f41c01b05feff7bf199c16266ea96c73ffa14c5, equal at both commits $ nice -n 19 gitleaks git . --config .gitleaks.toml --log-opts=origin/main..HEAD --redact --timeout 600 exit 0; 36 commits scanned; no leaks found (the pre-commit scans of cf42c6d08 and b0c11c324: no leaks) $ nice -n 19 python3 <the coordinator's merge-tree landing check> 463a57b98 b0c11c324 exit 0; clean three-way merge; merged-vs-main paths 17, outside PR-owned 0; main drift 30 paths, overlap 0; registry foreign rows equal, order preserved, PR-owned rows 16; merged files[] sorted, no duplicates (9571 rows); LANDABLE $ git push origin HEAD:claude/openhands-resolver-20260928 exit 0; pre-push registry tests: Ran 3 tests, OK; db24156b9..b0c11c324, no force Not run in this round: the host full suite (about 43 minutes here, which would overrun a scheduled measurement window; the CI full suites on db24156b9 are below) and the planted-defect mutations (recorded at 2ede7b871; no assertion has changed since). # Head b2d556c95, 2026-10-03 17:08-17:10Z (historical). Same TMPDIR convention. $ nice -n 19 python3 scripts/validate.py exit 0; {"components": 69, "hashed_files": 9429, "profiles": 4, "receipts": 187, "status": "passed"} $ nice -n 19 python3 -m unittest tests.test_runtime_worker_openhands_resolver tests.test_runtime_worker_openhands exit 0; Ran 248 tests in 19.862s; OK $ (home-path TMPDIR) nice -n 19 python3 -m unittest tests.test_runtime_worker_openhands_resolver tests.test_runtime_worker_openhands exit 0; Ran 248 tests in 20.310s; OK (skipped=2) $ nice -n 19 python3 blueprints/runtime-workers/openhands/resolver.py --help exit 0 $ nice -n 19 python3 blueprints/runtime-workers/openhands/resolver.py run --help exit 0 $ nice -n 19 git diff --check origin/main...HEAD exit 0 (origin/main ecea2865, merge base 59f8a1e36) $ git diff --name-only origin/main...HEAD exit 0; exactly the 17 contract paths $ nice -n 19 gitleaks git . --config .gitleaks.toml --log-opts=origin/main..HEAD --redact --timeout 600 exit 0; 34 commits scanned; no leaks found $ nice -n 19 python3 scripts/component_matrix.py --write exit 0; {"flip_rule_violations": 0, "rows": 32, "status": "written"}; no file changed $ nice -n 19 python3 scripts/new_host_grand_list.py --write exit 0; {"status": "written", "layers": 32, "winners": 66}; no file changed $ git push origin HEAD:claude/openhands-resolver-20260928 exit 0; pre-push registry tests: Ran 3 tests, OK; d35633fad..b2d556c95, no force # Head d35633fad, before the fixture repair, 16:55-16:57Z $ nice -n 19 python3 scripts/validate.py exit 0; "status": "passed" $ nice -n 19 python3 -m unittest tests.test_runtime_worker_openhands_resolver tests.test_runtime_worker_openhands exit 0; Ran 248 tests in 20.274s; OK $ (home-path TMPDIR) the same pair exit 1; Ran 248 tests in 20.300s; FAILED (failures=2) OutgoingGuardTests.test_host_paths_and_the_user_name_are_refused and PullRequestLoopTests.test_pr_body_follows_the_template_and_renders_model_text_inert: 'private_content' != 'host_path' # Clean-main comparison of the 11 non-OpenHands IDs that failed in the host full suite below $ git worktree add --detach <scratch> origin/main # ecea28654a835fff2cc3651bab77ca0e46b9bec5, clean $ git -C <scratch> checkout --detach 59f8a1e36 # the then-merged base, clean $ nice -n 19 python3 -m unittest <the 11 IDs> # same command in every tree and TMPDIR tree neutral TMPDIR home-path TMPDIR b2d556c95 exit 1; failures=1 exit 1; failures=9 d35633fad exit 1; failures=1 exit 1; failures=9 origin/main ecea2865 exit 1; failures=1 exit 1; failures=9 merged base 59f8a1e36 exit 1; failures=1 exit 1; failures=9 Within each TMPDIR, the failing IDs are identical on every tree: - under both: tests.test_windows_terminal_defaults.OverlayTests.test_the_installed_client_knows_no_notification_type_without_a_decision (the installed client knows a notification type, auth_storage_failure, that has no decision) - under the home-path TMPDIR only, in tests.test_token_e2e_grader: F19c_Stage3Mutants.test_M17c_manifest_canary_off, F19d_RepairRoundMutants.test_M56c_the_export_backstop_is_off, F29_Export (3 tests), F29b_CheckHtml (2 tests), F29c_ArgvSanitizer.test_a_grade_run_that_spells_its_flags_with_equals_records_no_path - passed on every tree under both: tests.test_gpt6_family_tiering_20260926.RunnerTests.test_sigterm_records_the_running_call_as_interrupted_without_counting_it, tests.test_order_throughput.CapacityRunTests.test_cli_refuses_live_base_url_from_env_file_without_network $ git worktree remove <scratch>; git worktree prune exit 0 # Host full suite, registry commit 96b96c681, home-path TMPDIR (coordinator run before the custody review round) $ nice -n 19 python3 -m unittest exit 1; Ran 10070 tests in 2568.426s; FAILED (failures=12, errors=1, skipped=850) 13 failing IDs: the 2 OpenHands fixture cases (repaired in 2ede7b871) and the 11 IDs compared above earlier control, superseded by the comparison above: the 11 IDs in a clean 4ced2923 clone, FAILED (failures=10, errors=1) # CI, read-only, 2026-10-03T19:57-19:59Z (gh api jobs and check-runs, gh run view --log, gh run download) db24156b9 validate job 111264954786: success. CI merge 69650a33 (db24156b9 into d2fc3803e); validate.py {"components": 69, "hashed_files": 9550, "profiles": 4, "receipts": 193, "status": "passed"}; component matrix {"rows": 32, "status": "checked"}; new-host grand list {"status": "passed", "layers": 32, "winners": 66}; python3 -m unittest: Ran 10078 tests in 1664.615s; OK (skipped=968) db24156b9 validate-macos job 111264957003: success at 19:29:18Z. full-suite-macos.log: Ran 10078 tests in 1794.871s; OK (skipped=1329); no FAIL or ERROR block; the alias test and both TMPDIR-repair tests ok db24156b9 required contexts: all eight success; a later validate re-run (job 111278594671) was cancelled at 19:56:39Z, after b0c11c324 was pushed b0c11c324 at 19:58:50Z: dependency-review, osv-scanner, sota-sources, token-report and verdict-review-gate success; validate and secret-scan in progress; validate-macos queued # CI, read-only, historical $ gh pr checks 489 --required # 2026-10-03T17:16:15Z b2d556c95: dependency-review, osv-scanner, secret-scan, sota-sources, token-report and verdict-review-gate pass; validate fail, job 111250877246: "files[2392]: files[] must be sorted by path (found 'docs/decisions/2026-10-03-omniroute-sdk-worker-0160.md' after 'docs/decisions/2026-10-03-retire-pr320-loki-denominator-host-receipts.md')", the pair main's job 111240392112 reports; validate-macos pending d35633fad: all eight passed: dependency-review, osv-scanner, secret-scan, sota-sources, token-report, validate (29m39s), validate-macos (36m58s), verdict-review-gate d35633fad validate job 111220987213: Ran 10070 tests in 1679.211s; OK (skipped=968) d35633fad validate-macos job 111220987307, full-suite-macos.log: Ran 10070 tests in 1849.584s; OK (skipped=1329) # Builder's sandbox record, before the 4ced2923 and 59f8a1e36 merges (superseded where marked). # Its first pair run, with the host Gitleaks wrapper, exited 1 on the wrapper's unavailable lock; # that failed attempt is retained separately, and PATH then selected native Gitleaks 8.30.1. $ nice -n 19 python3 -m unittest tests.test_runtime_worker_openhands_resolver.PatchValidatorTests exit 0; Ran 11 tests in 1.185s; OK $ nice -n 19 python3 -m unittest # superseded by the host and CI runs above exit 1; Ran 10046 tests; FAILED (failures=485, errors=195, skipped=863); errors=168 with native Gitleaks on PATH $ nice -n 19 gitleaks git . --config .gitleaks.toml --pre-commit --redact --timeout 600 exit 0; actual working diff scanned; no leaks found $ nice -n 19 python3 scripts/validate.py # superseded: the 4ced2923 merge brought main's AGENTS.md exit 1; only the AGENTS.md SHA-256 and byte-count mismatch ``` These are repository integration checks, not unchanged upstream acceptance suites. **CI on this head.** The workflows test GitHub's merge of the head with main. On the reviewed head `db24156b9`, all eight required contexts passed: - `validate` job `111264954786` tested merge `69650a33` (`db24156b9` into `d2fc3803e`). `validate.py` reported `"status": "passed"` with 9,550 hashed files and 193 receipts. The component matrix and new-host grand list checks passed. `python3 -m unittest` ran 10,078 tests: `OK (skipped=968)`. - `validate-macos` job `111264957003` passed. Its `full-suite-macos.log` shows 10,078 tests, `OK (skipped=1329)` and no FAIL or ERROR block. The merged registry is sorted. The `b2d556c95` `validate` failure (job `111250877246`) on main's unsorted registry pair no longer applies. The new head `b0c11c324` changes only the decision record, `RESOLVER.md`, one test's comment and skip text, and three registry rows. Its required contexts were still running when this description was written. The head that lands must show all eight SUCCESS, and a macOS full-suite artifact with no failure in `tests.test_runtime_worker_openhands_resolver`. **Linux full-suite acceptance item.** - CI's Linux and macOS full suites passed on `db24156b9`, which differs from `b0c11c324` only in the files listed above. - On the host, the PR's two test modules pass at `b0c11c324` under both `TMPDIR`s. - The host full suite was not re-run in this round. At `b2d556c95`, its 11 other failing IDs failed identically on clean main and on the then-merged base, environment by environment. ### Review round The custody review of `d35633fad` (independent Opus 5.5, read-only) returned **repair**. This is its one repair round. Numbers are the findings' indices in the review record, counted from 0, as in commit `2ede7b871`'s message. | # | Severity | Finding | Disposition | | --- | --- | --- | --- | | 0 | should-fix | The description still described the state before the custody merge (`4ced2923` unmerged, `validate.py` exit 1) | Fixed. Scope, the SOTA "Repository" bullet, the evidence table and the commands now state the merged state: base `59f8a1e36` (merged in `d35633fad`), with `4ced2923` merged in `85830e815`. `scripts/validate.py` with a neutral `TMPDIR`: exit 0, `"status": "passed"` at `d35633fad` and `b2d556c95`. The builder's exit 1 remains only as superseded history | | 1 | should-fix | The Linux full-suite state was contradictory, with no recorded clean-main comparison | Fixed. "Local commands run" records the comparison: a fresh detached worktree, at origin/main `ecea2865` and then at the merged base `59f8a1e36`, the 11 IDs, the command and every exit code under two `TMPDIR`s. The failing sets match this head's. The builder's sandbox numbers are marked superseded, and the "remains an acceptance blocker" paragraph is replaced by the evidence summary | | 2 | minor | "Including unittest's trailing spaces" is false for the fail-first logs | Fixed. The clause is removed. The blob SHAs `ed55377f` and `3f41c01b` are unchanged from `501bcc9e`. The same wording in the custody contract, which lives outside the repository, is reported to the coordinator | | 3 | minor | The home-path `TMPDIR` failure was called an environment artifact, but the fixtures and the check order come from this PR | Fixed in `2ede7b871` (tests only), with its registry row in `b2d556c95`. A synthetic absolute host root serves the two `host_path` assertions. The symlink case probes its prerequisite, following git's `test_lazy_prereq` pattern, and skips its two subtests with an explicit message. No assertion or reason label changed. Fail-first at `d35633fad`: exit 1, failures=2. After the fix: exit 0 under both `TMPDIR`s. Two planted defects are caught (see the evidence table) | | 4 | minor | `validate-macos` had not run on `d35633fad` | Closed for `d35633fad`: job `111220987307` passed, and its log shows `OK (skipped=1329)` with the alias test `ok`. On `b2d556c95`, `validate-macos` is pending and `validate` failed on main's registry order; see "CI on this head" | | 5 | minor | The reviewer did not re-run the local acceptance commands | Closed: the final-head runs and their exit codes are recorded above | | 6 | minor | The reviewer did not download the historical macOS artifact | No change needed. Artifact `11015337319` was re-downloaded read-only in this round, and its three FAIL blocks are cited in the evidence table | | 7 | minor | Neither contract review has a recorded verdict | Open and listed as pending: 6(a), GPT-6.1 Astra/max, after 19:03Z when the GPT-free slot ends; 6(b), the Opus closure review of `b2d556c95`. The PR had no review threads at 17:16Z | ### Step 6 repair round This is the one repair round for the two step 6 reviews of `db24156b9`. A is the GPT-6 Astra/max review, and O1-O9 are the Opus closure review's findings in the order listed under "Step 6 reviews". The fixes are in `cf42c6d08`, with their registry rows in `b0c11c324`. | # | Severity | Finding | Disposition | | --- | --- | --- | --- | | A | should-fix | Fork option prerequisites; the runbook permits a run after either choice; CI egress and final message; the fork guarantee is unverified | **Fixed.** The record's option 2 now states that the harness pushes to and opens PRs only in this repository, and lists what option 2 needs before a first run: a fork remote and push-URL check, `--head <owner>:<branch>`, the rules lookup and a `non_fast_forward` ruleset on the fork, and its own review. CI egress and condition 3 are addressed under both options, and the "not re-read" caveat is kept. The `RESOLVER.md` runbook precondition now also stops for option 2 until that change lands. The amendment heading, record lines 1-15 and the live-run wait are unchanged | | O1 | should-fix | Option 2 incomplete; filed under the wrong kind of change; condition 3; the fork's owner | **Fixed** with A. `RESOLVER.md` Residuals separate the egress block (a workflow change outside this PR) from the fork option (a change to this PR's harness). The record names the fork's owner: the repository's owning User account, which is also the admin login the resolver acts through. The amendment summary in `RESOLVER.md` is updated to match | | O2 | should-fix | The PR body describes `b2d556c95` | **Fixed** in this description: base and head, the merge list, "CI on this head", the evidence rows, and the local commands at `b0c11c324` with exit codes | | O3 | minor | The skip message is too narrow | **Fixed.** The comment and skip reason name any `scripts/validate.py` `PRIVATE_CONTENT` pattern, such as a personal home path. No assertion changed, and the reworded reason appears in the home-path `TMPDIR` run | | O4 | minor | The G4 reason-code order is wrong | **Fixed** in the `RESOLVER.md` G4 residual and under "What is not done" below | | O5 | minor | `validate-macos` on `db24156b9` | **Closed for `db24156b9`:** job `111264957003` passed, and its artifact is cited in the evidence table. **Open:** `validate-macos` on `b0c11c324` | | O6 | minor | The 6(a) review is pending | **Closed:** 6(a) returned (A above). **Open:** the reviewers' re-read of this delta | | O7 | minor | Main moved after the custody merge | **Open, not merged in this round.** The landing check against `463a57b98` reports LANDABLE. Contract step 7's "repeat steps 2 and 7" remains the coordinator's call before landing | | O8 | minor | The step-5 commands were not re-run | **Closed at `b0c11c324`**, except the host full suite and the planted-defect mutations (see "Local commands run") | | O9 | minor | Verification record | No change needed | ### Decision record `docs/decisions/2026-09-28-openhands-resolver-isolation.md` records the resolver-mode narrowing and its amendment, **proposed 2026-09-28 and decided 2026-10-04: option 1 with trusted pre-push enforcement**. The decision section records the following: - the owner's delegation, in their words: "max quality sota convergenced resolution automation workflow at highest quality"; - the command center's proposal (option 1 with an in-CI tripwire); - the GPT-family job 004 vote: disagree on sufficiency, because a check inside PR CI cannot protect against the commit under test. Each reason is re-checked against the GitHub, OpenSSF Scorecard and zizmor sources; - the gate and its trusted-copy invariant; - the separate defence-in-depth PR for workflow hardening; - the residuals, the evidence, and the overturn to option 2 if the gate cannot be kept immutable to the agent. Option 2's text stays as the alternative; only its line citations moved with the harness change. The history below describes the amendment before the decision. After `cf42c6d08` and the wording fixes `f4e7aa2a2` and `54438ce7f`, the amendment's option 2: - states that the resolver as built pushes to and opens PRs only in this repository; - lists the separately reviewed harness change and fork ruleset it needs before a first run; - marks the fork's holder undetermined: an organization the owner creates, or a second account. The choice changes the push identity, the fork's ruleset and the `--head <holder>:<branch>` value; - sources the token and secret guarantee, for `pull_request` runs from a fork, in GitHub's "Workflows in forked repositories". Both options now address condition 3 and CI egress. The 2026-10-03 fixture-repair section records native Git sources, the skipped-check alternative, the argument-normalization completeness finding, evidence limits and the native macOS condition that would overturn the repair. Lines 1-15 remain unchanged. ### What is not done, and what needs the owner - **Owner decision: decided 2026-10-04.** It chose option 1 with trusted pre-push enforcement; the owner delegated the choice to converged practice. Still open: - workflow hardening, in a separate defence-in-depth PR: `permissions: {}` defaults, `persist-credentials: false`, cache, runner and timeout policy, a protected zizmor configuration, and a strict tripwire test on main. Until then, code under test runs with network, and that residual is accepted; - the first live run, which waits until this gate lands on main, its negative controls pass there and the stage gates are recorded; - the protected list, which is broad by design: all of `tests/**`, and every file a reachable step names. A resolver task that needs those files fails at the gate with no push; - option 2, an owner fork, which stays the overturn target and would need its own harness change. Resolver-PR check results are still not evidence of model-code safety. - G4 remains unrecorded. Because no `stage-gates.json` exists, a real run today refuses earlier, at the gates stage, with `stage_gates_not_recorded`. Once the recorded stage gates and G5 pass, it refuses with `stage_gate_g4_not_recorded` until the coordinator records the isolated reviewer argv hash. - G5 and `stage-gates.json` remain required. Both gateways' provider settings and the confinement design still need their own acceptance. - These remain separate required steps: - fresh P0-P2 receipts, P3-P5 and G2 image qualification; - the reviewers' re-read of the step 6 delta; - the required contexts on the final head; - the first live draft-PR attempt. The native macOS check of the alias repair and the `TMPDIR` repair passed on `db24156b9`. A7's environment-name read at teardown stays in place. ### Host evidence Not applicable: no file under `evidence/hosts/` changes. The historical macOS artifact is distinguished from a new native run, and no live resolver acceptance is claimed. ### Checklist - [x] No GitHub Actions or workflow files changed; workflow hardening remains a separate defence-in-depth PR. - [x] New Actions permissions or pins are not introduced by this change. - [x] No credential value was read or published. Gitleaks scans of the history (36 commits at `b0c11c324`) and of both step 6 commits report no leaks, and the pre-push registry tests passed. - [x] No new paid hosting, subscription or billing surface. - [x] Peer-owned files and worktrees preserved. - [x] Separate Stage 2 GPT review and whole-head Opus closure verdicts recorded, including residuals. - [ ] The reviewers' re-read of the step 6 delta recorded. - [ ] Every review thread resolved and all eight required contexts SUCCESS on the pushed head.
Scope
openai-codex,openai-codex-cli-bin) from 0.159.3 to rust-v0.160.0. It brings every current-pin site along: tests, landscape snapshot, generated reports, prose and the dashboard checkpoint. It adds the qualification receiptruntime-sdk-20261003.codex-rs/app-server-daemon/README.md:127-128, that switch must usecodex app-server daemon update --from-cli.56473e4b8lane:shared.manifests/stack.json,manifests/evidence.json,observability/grand-dashboard/state.jsonandadoption/sdk/.blueprints/us-equities/workers/requirements.txt:1,openai-codex==0.159.3→==0.160.0.adoption/new-wsl/**,evidence/artifacts/new-wsl-*, the definitive manifest) are untouched.SOTA sources
a956835d020762cb2b570053af06f643a11c0ecc, published 2026-10-01T20:19:13Z). The current stable release.sdk/pythonis byte-identical to rust-v0.159.2/0.159.3 (tree297fc74e). The config schema delta is additive: six property paths, no removals.codex-rs/stateadds no SQL migrations.@openai/codex@0.160.0.dist.integritymatched the downloaded bytes; sha256373517768e912eeb5054024ae9215e2c90a1420957b66fe134ef745a00948d4a.openai-codex0.160.0 (wheel sha25661d2d855…,requires_dist openai-codex-cli-bin==0.160.0) andopenai-codex-cli-bin0.160.0.adoption/sdk/README.mdcommand from the repository root.Evidence-class table
codex-cli 0.160.0(sha25612eb3e81…);codex exec --helpis unchanged from 0.159.3native_proven(this host)evidence/artifacts/runtime-sdk-20261003/receipt.jsonuv pip checkpass in a fresh venvnative_proven3a17fa09…native_proven(marker turns only)Local commands run
Reviews
blueprints/us-equities/workers/README.md:3still says SDK 0.159.2 (trading owner).recipes/README.md:67is a historical complete-package hash.Decision record
No new decision document. The pin follows the standing currency practice, and the qualification is
evidence/receipts/runtime-sdk-20261003.json. The move falls inside the 7-day cooldown thatdocs/decisions/2026-09-25-workstation-sota-refresh.mdapplied to non-security releases, as the 0.159.2 and 0.159.3 moves did. NativeStack2604 already runs 0.160.0.Host evidence
No files under
evidence/hosts/change.Checklist
🤖 Generated with Claude Code